Anant Shrivastava

@anantshri.info

Researcher | Trainer | Security Professional | Developer | Admin

I wanted a simple JSON API to fetch my BOINC stats and badges for my website. There was no clean endpoint, so I built one. boincstats.apps.anantshri.info It is still scraping, just done once on my side instead of everyone doing it badly. You get clean JSON, updated every 24 hours.

BOINC Stats - Cross-Project Statistics

Unified BOINC statistics across all projects. Search by CPID or username to view your aggregated stats and badges.

boincstats.apps.anantshri.info

I have been building zero install security tools where the browser is the base. I wrote about the “why” here: blog.anantshri.info/making-secur... I realized many others are building similar browser-first tools, so I made a curated collection: anantshri.github.io/awesome-in-b... PRs & links welcome

Awesome In-Browser Security Tools

A curated list of open-source security tools that run entirely in your browser — no backend, no installation required.

anantshri.github.io

SBOMPlay v0.0.7 - Custom SBOM support - Improved SBOM auditor: checks against baselines - EOX detection (EOL and EOS) - Dependency confusion detection - Clear rate limit warnings - Explicit list of outbound hosts for paranoid self-hosting deployment cyfinoid.com/sbomplay-v0-...

Introducing SBOMPlay v0.0.7: Enhanced Features Unveiled

Explore the latest updates in SBOMPlay v0.0.7, featuring enhanced capabilities, custom SBOM support, and improved auditing tools.

cyfinoid.com

All the new 3rd party modules must not be installed immediately, unless its a critical zero day, unless the author informs you to do so, unless a gazillion other exceptions. Infosec needs to make up their mind what should dev/admins do. and ya everyone with buy my product can go to hell.

🚨 BLACK FRIDAY MEGA SALE 🚨 All Cyfinoid security tools are 100% OFF! Get our security tools for the low price of $0.00! SBOM analyzer? FREE 3PTracer? FREE Act fast! This deal expires in... *checks notes* ...never. Because they've always been free cyfinoid.github.io

Cyfinoid Research - Security Tools & Projects

Cyfinoid's collection of security tools and research projects including software supply chain analysis, Android assessment, cloud security, and more.

cyfinoid.github.io

Everyone talking about npm hacks. But is it really more attacks or just more visibility? Maybe attackers are piling on npm Maybe the ecosystem is just easier to monitor Maybe sloppy practices make it an easy catch What nags me more: silence in PyPI, RubyGems, Maven. No attacks, or no one looking?