Skip to content
Change the repository type filter

All

    Repositories list

    • OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
      TypeScript
      MIT License
      17k001Updated Sep 12, 2025Sep 12, 2025
    • terragoat

      Public
      TerraGoat is Bridgecrew's "Vulnerable by Design" Terraform repository. TerraGoat is a learning and training project that demonstrates how common configuration e…
      HCL
      Apache License 2.0
      5.7k006Updated Dec 15, 2024Dec 15, 2024
    • Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀
      HTML
      MIT License
      958001Updated Dec 15, 2024Dec 15, 2024
    • cicd-goat

      Public
      A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.
      Python
      Apache License 2.0
      3890023Updated Nov 28, 2023Nov 28, 2023
    • WebGoat

      Public
      WebGoat is a deliberately insecure application
      JavaScript
      Other
      7.4k0010Updated Nov 27, 2023Nov 27, 2023
    • NodeGoat

      Public
      The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how to effecti…
      HTML
      Apache License 2.0
      2.3k004Updated Oct 10, 2023Oct 10, 2023
    • GitHub Actions Goat: Deliberately Vulnerable GitHub Actions CI/CD Environment
      JavaScript
      Apache License 2.0
      303000Updated Sep 25, 2023Sep 25, 2023
    • .github

      Public
      0000Updated Sep 25, 2023Sep 25, 2023
    • Vulnerable by design testbed repository for Spectral scanner.
      Jupyter Notebook
      131001Updated Sep 25, 2023Sep 25, 2023
    • metarget

      Public
      Metarget is a framework providing automatic constructions of vulnerable infrastructures.
      Python
      Apache License 2.0
      199000Updated Mar 13, 2023Mar 13, 2023