Self-hosted GitHub security dashboard — tracks org security checks (MFA, branch protection, scanning) with score trends, plus automated Actions cache cleanup. FastAPI + Next.js + PostgreSQL.
-
Updated
Oct 6, 2026 - JavaScript
Self-hosted GitHub security dashboard — tracks org security checks (MFA, branch protection, scanning) with score trends, plus automated Actions cache cleanup. FastAPI + Next.js + PostgreSQL.
GitGoat is an open source tool that was built to enable DevOps and Engineering teams to design and implement a sustainable misconfiguration prevention strategy. It can be used to test products with access to GitHub repositories without a risk to your production environment.
Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive files
Security, maintenance, and audit for your GitHub account and organizations
GitHub security posture analysis for AI agents — 39 MCP tools, 45 checks across org, repos, Actions, secrets, supply chain, and access control
Detect and clean up after the PolinRider supply-chain campaign — GitHub organizations, personal accounts, and macOS/Linux/Windows machines. Shell only, dry-run by default.
Supply-chain malware scanner for Git repos. Finds droppers committed into the repo itself — the kind npm audit can't see because there's no malicious dependency. Runs on git clone or when VS Code opens the folder. Kills the loader, scans every repo you can reach, purges it from history.
Ready-to-wear project templates for GitHub repositories 👔
GitHub API Data Gatherer, Supports multi-token rotation, deep fetching, field filtering, and linked requests. Built as a proxy to the official GitHub API, it's fully compatible with the official API. ⚡ GitHub API数据采集器,支持多Token轮换、深度爬取、字段过滤,以及联动请求等功能。基于GitHub API代理实现,完全兼容官方API
VS Code extension for project Credential Digger https://github.com/SAP/credential-digger
API-based platform for hunting exposed secrets across GitHub repositories
gitghost — find secrets in a GitHub account's public repos, including ones 'deleted' but still recoverable from git history. Exposure score + HTML dossier. Detection-only, zero dependencies.
ClaudeRabbit is a free, open-source security product protecting the open-source community from malware. We clone any public GitHub repo into an isolated sandbox, run it, and return one honest safety score.
How to identify, analyze, and report targeted phishing campaigns on GitHub — with real-world case studies and a step-by-step takedown workflow.
Cloud-hosted gitleaks for GitHub - hunt leaked API keys, wallet private keys & secrets across 40 services. PR refs + full git history + parallel scanning. Apify actor.
An extensive documentation library with guides and examples for optimizing workflows, fostering collaboration, and securing deployments through GitHub's diverse toolset.
Github native application for organisations; uses OpenAI models to identify Security Risks introduced by PRs
Hands‑on examples of extending KICS to detect GitHub Actions exploitation techniques.
Personal security gate — scan for secrets, CVEs, and risk signals before you push or use a repo
Defensive GitHub trust & repository security auditor for static analysis, wallet security, secret exposure and suspicious code signals.
To associate your repository with the github-security topic, visit your repo's landing page and select "manage topics."