Terraform modules are not protected by the Dependency Lock File, consequently, a seemingly harmless module could potentially introduce malicious code
Example repository for GitHub Actions Time of Check to Time of Use (TOCTOU vulnerabilities)
Many public and popular libraries that have long been abandoned are still being used in huge projects. Access to projects can be hijacked through domain name purchases
Unclaimed WordPress plugins are vulnerable to takeover via the plugin directory
Attacking misconfigured pipelines that use OIDC
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.