LunaTrace is an Open Source supply chain security and auditing tool. At its heart is a web console the tracks your projects and their dependencies, looking for vulnerabilities and other issues. This console is provided as a SAAS (available here for free) or you can deploy it and manage it yourself. Please see our LunaTrace documentation for more information. We're a team of Security Engineers on a mission to make awesome Open Source Application Security tooling. It all lives in this monorepo and here's a breakdown of where everything we've built lives. LunaTrace: A free alternative to services like GitHub Dependabot or Snyk that automatically monitors for your dependencies for vulnerabilities. It automatically integrates with GitHub Pull Requests to notify you of new CVEs before you deploy to production. Try it out in one-click via our GitHub App. Status: Production ready and under active development (our primary focus). Log4Shell CLI: A small command line utility to scan for Log4Shell. Also supports patching JAR files against Log4Shell, scanning running processes on your system, and more. Follow our Mitigation Guide for more context.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
Finds publicly known security vulnerabilities in a website's frontend JavaScript libraries.
A non-profit organization focused on improving the security of software through resources and training.
Amass by OWASP performs comprehensive attack surface mapping and asset discovery.
Automate your reconnaissance process with AttackSurfaceMapper, a tool for mapping and analyzing network attack surfaces.
An extensible, heuristic-based vulnerability scanning tool for installed npm packages.
A Java based HTTP/HTTPS proxy for assessing web application vulnerability with various useful features.
A collection of resources for securing AWS environments using the CIS Amazon Web Services Foundations Benchmark 1.1
iOS application for testing iOS penetration testing skills in a legal environment.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.