SaaSHub helps you find the best software and product alternatives Learn more →
Top 23 HTML Security Projects
-
-
SaaSHub
SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives
-
YubiKey-Guide
Community guide to using YubiKey for GnuPG and SSH - protect secrets with hardware crypto.
Project mention: Community guide to using Yubikey for GnuPG and SSH | news.ycombinator.com | 2026-04-16 -
school-of-sre
At LinkedIn, we are using this curriculum for onboarding our entry-level talents into the SRE role.
-
-
Project mention: We found a stable Firefox identifier linking all your private Tor identities | news.ycombinator.com | 2026-04-22
In addition to server-side bits like IP address, request headers and TLS/TCP fingerprints, there are some client-side things you can do such as with media queries, either directly via CSS styles or elements that support them directly like . You can get things like the installed fonts, screen size/type or platform/browser-specific identifiers.
https://fingerprint.com/blog/disabling-javascript-wont-stop-...
There is also a method of fingerprinting using the favicon: https://github.com/jonasstrehle/supercookie
-
-
kubernetes-goat
Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀
-
-
-
-
Project mention: When internal hostnames are leaked to the clown | news.ycombinator.com | 2026-02-04
-
-
This is the failure mode I wrote about in The Only Guarantee Is Your Catalog Will Be Wrong. Eventually. and again in The Missing Part of the Pipeline. The structural answer is to wrap the bridge story onto the data at the moment of ingest, with claim-level granularity, signed and immutable, and let it ride with the data through every downstream transform. Provenance has to be a property of the artifact, not a layer reconstructed afterward by a catalog crawling artifacts that have already lost their context. Every downstream consumer inherits the wrap for free. The model reading the data can tell that the regulator's chunk supersedes the intern's chunk because that fact is in the manifest the chunk carries with it. The SLSA specification defines this primitive for software builds. The same primitive is what the data world has been missing.
-
Project mention: 1k Data Breaches Later, the Disclosure Lag Is Worse | news.ycombinator.com | 2026-06-08
I've had a similar thought, where each company making over a certain amount of money per year must begin a VDP (and optionally a BBP) so that security flaws can be reported to them easily. This can easily be done by simply opening up security@companydomain and using security.txt (https://securitytxt.org). Reports must receive a response in N days, where N is calculated based on available staff, resource allocation, and revenue of the company.
-
Project mention: Show HN: DropLock – E2EE secret sharing web app with no back end | news.ycombinator.com | 2026-06-02
-
awesome-anti-forensic
Tools and packages that are used for countering forensic activities, including encryption, steganography, and anything that modify attributes. This all includes tools to work with anything in general that makes changes to a system for the purposes of hiding information.
-
-
-
-
gapps
Security compliance platform - SOC2, CMMC, ASVS, ISO27001, HIPAA, NIST CSF, NIST 800-53, CSC CIS 18, PCI DSS, SSF tracking
-
grapheneos.org
Servers for our website, HTTP/HTTPS connectivity checks, HTTPS network time, NTP (for Qualcomm XTRA), Broadcom PSDS cache, Samsung PSDS cache, Qualcomm PSDS (XTRA) cache, SUPL proxy, attestation key provisioning proxy, Vanadium component update check/download proxy, network location proxy and geocoding proxy. Also app and OS updates via an include.
Project mention: How to Install and Start Using LineageOS on Your Phone | news.ycombinator.com | 2026-03-06you can easily change the launcher & keyboard to whatever you want on GrapheneOS. About ebay, check https://github.com/GrapheneOS/grapheneos.org/issues/1351
-
Project mention: From Active Learning to Deliberate Practice: an iximiuz Labs case study | dev.to | 2026-03-24
This is a playground set up to give the learner practice with running a vulnerability scanning tool (in this case, kubescape) to identify and fix a randomized security vulnerability from the OWASP Kubernetes Top 10 list in a running cluster.
-
HTML Security discussion
HTML Security related posts
-
1k Data Breaches Later, the Disclosure Lag Is Worse
-
The Website Specification
-
Apparently Google hates us now
-
For Londoners, a Roman Bridge Still Determines Your Commute
-
96% of GitHub repos have high severity issues in their Action workflows
-
Supply Chain Security Proxy: Move Beyond Vulnerability Scanning
-
Community guide to using Yubikey for GnuPG and SSH
-
A note from our sponsor - SaaSHub
www.saashub.com | 10 Jun 2026
Index
What are some of the best open-source Security projects in HTML? This list will help you:
| # | Project | Stars |
|---|---|---|
| 1 | KeeWeb | 12,937 |
| 2 | YubiKey-Guide | 12,347 |
| 3 | school-of-sre | 8,116 |
| 4 | cve | 7,855 |
| 5 | supercookie | 7,058 |
| 6 | Security-101 | 6,519 |
| 7 | kubernetes-goat | 5,664 |
| 8 | js-xss | 5,319 |
| 9 | django-DefectDojo | 4,740 |
| 10 | Web-Security-Learning | 4,302 |
| 11 | 1Hosts | 2,090 |
| 12 | ICS-Security-Tools | 1,940 |
| 13 | slsa | 1,876 |
| 14 | security-txt | 1,862 |
| 15 | portable-secret | 1,737 |
| 16 | awesome-anti-forensic | 995 |
| 17 | railsgoat | 921 |
| 18 | ffprofile | 851 |
| 19 | i2pdbrowser | 792 |
| 20 | gapps | 673 |
| 21 | grapheneos.org | 666 |
| 22 | www-project-kubernetes-top-ten | 613 |
| 23 | istlsfastyet.com | 427 |