Skip to content
View andrew's full-sized avatar
🚙
I may be slow to respond.
🚙
I may be slow to respond.

Sponsors

@balupton
@doanson0831783
@hasky00

Sponsoring

Block or report andrew

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Starred repositories

Showing results

Code and data used to create the examples in "Evidence-based Software Engineering based on the publicly available data"

R 420 48 Updated Sep 9, 2025

Issue handling for Evidence-based Software Engineering: based on the publicly available data

283 17 Updated Apr 5, 2025

🔎 Static code analysis engine to find security issues in code.

OCaml 1,972 158 Updated Dec 22, 2025

Converted security rules fromcodeql to semgrep format.

1 Updated Dec 21, 2025

Content for GitHub profile

Ruby 9 Updated Dec 22, 2025

Jekyll plugin that generates site statistics

Ruby 1 Updated Dec 21, 2025

An open API service providing security vulnerability metadata for many open source software ecosystems.

Ruby 1 Updated Dec 15, 2025

ripgrep recursively searches directories for a regex pattern while respecting your gitignore

Rust 58,282 2,343 Updated Dec 17, 2025

Manager of third-party sources of Semgrep rules 🗂

Python 92 7 Updated Jul 21, 2024

Repository to support analyzing energy system design models based on data

Python 20 10 Updated Dec 22, 2025

The pattern matching swiss knife

C 9,291 1,544 Updated Nov 26, 2025

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

OCaml 13,671 843 Updated Dec 23, 2025

A curated dataset of known package typosquats from public security research. Maps malicious packages to their legitimate targets with ecosystem, classification, and source attribution.

3 1 Updated Dec 17, 2025

fuzz parameter generator from json-schema

Ruby 7 1 Updated Aug 13, 2025

🌴 TreeHaver is a cross-Ruby adapter for the tree-sitter & citrus parsing libraries; supporting MRI Ruby, JRuby, & TruffleRuby. Provides unified parsing API & AST when using ruby_tree_sitter, citrus…

Ruby 14 Updated Dec 21, 2025

Detect potential typosquatting packages across package ecosystems

Ruby 2 Updated Dec 17, 2025

Generate and verify lockfiles for GitHub Actions dependencies.

TypeScript 45 1 Updated Dec 22, 2025

Checksums for GitHub Actions.

Go 17 1 Updated Dec 18, 2025

🌉 A bridge between decentralized social networks

Python 1,118 56 Updated Dec 22, 2025

🍺 Alcoholless: lightweight security sandbox for Homebrew (and others)

Go 84 2 Updated Dec 22, 2025
Java 2 Updated Dec 20, 2025

Parse, generate, and validate Software Bill of Materials (SBOM)

Ruby 1 Updated Dec 14, 2025

A utility to generate SPDX-compliant Bill of Materials manifests

Go 428 63 Updated Dec 15, 2025

Open Infrastructure Map, a view of infrastructure data in OpenStreetMap

TypeScript 332 60 Updated Dec 11, 2025

A regular dump of the most-downloaded packages from PyPI

HTML 248 16 Updated Dec 1, 2025

Library to ingest and generate SBOMs

HTML 35 17 Updated Dec 19, 2025

Create a contribution report based on contribution and sponsorsip by an organization or people with domains related to a given org

Python 4 Updated Dec 12, 2025

A GitHub Action used for publishing an Action to ghcr.io as an OCI container.

TypeScript 113 11 Updated Aug 8, 2025
Jupyter Notebook 12 23 Updated Dec 16, 2025

Schema.org profile for software types

8 2 Updated Mar 10, 2025
Next