Skip to content
View andrew's full-sized avatar
🚙
I may be slow to respond.
🚙
I may be slow to respond.

Sponsors

@balupton
@doanson0831783
@hasky00

Sponsoring

Block or report andrew

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Starred repositories

Showing results

Who owns your dependencies

Python 2 Updated Dec 1, 2025

⚙️ A curated list of static analysis (SAST) tools and linters for all programming languages, config files, build tools, and more. The focus is on tools which improve code quality.

Rust 14,282 1,409 Updated Dec 26, 2025

A plugin for Jekyll to generate a feed in ActivityPub format

Ruby 11 1 Updated Aug 4, 2025

A suite of utilities to help with software supply chain challenges on nix targets

Python 225 30 Updated Nov 12, 2025

GemGuard is your one-stop solution for Ruby supply chain security. Detect vulnerabilities, identify typosquats, generate SBOMs, and secure your dependencies with enterprise-grade tooling designed f…

Ruby 13 1 Updated Sep 2, 2025

Go-style imports for Ruby

Ruby 1 Updated Dec 25, 2025

Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact provenance.

Go 511 74 Updated Dec 22, 2025

Parse changelog files into structured data

Ruby 5 Updated Dec 23, 2025

mmdb-server is an open source fast API server to lookup IP addresses for their geographic location.

Python 184 26 Updated Dec 22, 2025

Code and data used to create the examples in "Evidence-based Software Engineering based on the publicly available data"

R 420 48 Updated Sep 9, 2025

Issue handling for Evidence-based Software Engineering: based on the publicly available data

283 17 Updated Apr 5, 2025

🔎 Static code analysis engine to find security issues in code.

OCaml 1,978 161 Updated Dec 26, 2025

Converted security rules fromcodeql to semgrep format.

1 Updated Dec 21, 2025

Content for GitHub profile

Ruby 9 1 Updated Dec 26, 2025

Jekyll plugin that generates site statistics

Ruby 1 Updated Dec 21, 2025

An open API service providing security vulnerability metadata for many open source software ecosystems.

Ruby 1 Updated Dec 15, 2025

ripgrep recursively searches directories for a regex pattern while respecting your gitignore

Rust 58,374 2,344 Updated Dec 17, 2025

Manager of 14 third-party sources comprising approximately 4,000 Semgrep rules 🗂

Python 92 6 Updated Dec 24, 2025

Repository to support analyzing energy system design models based on data

Python 20 10 Updated Dec 23, 2025

The pattern matching swiss knife

C 9,302 1,546 Updated Nov 26, 2025

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

OCaml 13,709 843 Updated Dec 26, 2025

A curated dataset of known package typosquats from public security research. Maps malicious packages to their legitimate targets with ecosystem, classification, and source attribution.

3 1 Updated Dec 17, 2025

fuzz parameter generator from json-schema

Ruby 7 1 Updated Aug 13, 2025

🌴 TreeHaver is a cross-Ruby adapter for the tree-sitter & citrus parsing libraries; supporting MRI Ruby, JRuby, & TruffleRuby. Provides unified parsing API & AST when using ruby_tree_sitter, citrus…

Ruby 14 Updated Dec 27, 2025

Detect potential typosquatting packages across package ecosystems

Ruby 2 Updated Dec 17, 2025

Generate and verify lockfiles for GitHub Actions dependencies.

TypeScript 47 Updated Dec 23, 2025

Checksums for GitHub Actions.

Go 17 1 Updated Dec 18, 2025

🌉 A bridge between decentralized social networks

Python 1,117 55 Updated Dec 27, 2025

🍺 Alcoholless: lightweight security sandbox for Homebrew (and others)

Go 85 2 Updated Dec 22, 2025
Java 3 Updated Dec 20, 2025
Next