Jeremy Long's repositories
DependencyCheck
OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.
musical-octo-carnival
A journey through the insecure defaults in GitHub Actions - wait who committed code to my repo?
GrokAssembly
Mono/.NET Project to get information about an assembly. Primarily for OWASP Dependency Check
checkmarx-github-action
Checkmarx Scan Github Action
dependency-check-plugin
Jenkins plugin for OWASP Dependency-Check. Inspects project components for known vulnerabilities (e.g. CVEs).
nist-data-mirror
A simple Java command-line utility to mirror the CVE XML and JSON data from NIST.
lein-dependency-check
A leiningen plugin for detecting vulnerable project dependencies
sbt-dependency-check
SBT Plugin for OWASP DependencyCheck. Monitor your dependencies and report if there are any publicly known vulnerabilities (e.g. CVEs).
Audio
Teensy Audio Library
avdweb_DAC16
Cheap 16 bit DAC AD5662 for the Arduino
burp-retire-js
Burp/ZAP/Maven extension that integrate Retire.js repository to find vulnerable Javascript libraries.
class-file-format-rule
A maven-enforcer rule that ensures dependencies do not exceed the required class file format for a particular JVM.
CPE-Parser
A utility for validating and parsing Common Platform Enumeration (CPE) v2.2 and v2.3 as originally defined by MITRE and maintained by NIST
cx-flow
Checkmarx Scan and Result Orchestration
homebrew-core
🍻 Default formulae for the missing package manager for macOS
jobrunr
An extremely easy way to perform background processing in Java. Backed by persistent storage. Open and free for commercial use.
juice-shop-assessment
Presentation and code from OWASP AppSec DC 2019 - "Testing With Your Left Foot Forward"
librosa
Python library for audio and music analysis
Looper
Teensy based audio looper
ossindex-public
Sonatype OSS Index - Public
packageurl-java
Java/JVM implementation of the package url spec
retire.js
scanner detecting the use of JavaScript libraries with known vulnerabilities
sonic
Simple library to speed up or slow down speech
violation-comments-lib
Library for commenting things with violations from static code analysis.
violations-lib
Java library for parsing report files from static code analysis.