Skip to content
View harekrishnarai's full-sized avatar
:octocat:
Securing apps via pentesting, code reviews & supply chain defense 🔐
:octocat:
Securing apps via pentesting, code reviews & supply chain defense 🔐

Block or report harekrishnarai

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
harekrishnarai/README.md

Hey there, I'm Hare Krishna Rai

Twitter Badge    LinkedIn Badge

CRTP Certification    eWPTX Certification


🎯 Security Researcher | Speaker | Open Source Contributor

I'm a Product Security Engineer at Okta (Auth0 Team), where I focus on securing the software supply chain. My passion lies in offensive security research, tool development, and sharing knowledge with the community.

  • 🔒 Creator of SCAGoat, a vulnerable-by-design application to benchmark SCA tools and simulate supply chain attacks.
  • 🧰 Regular secure coding trainer, conference reviewer, and CTF enthusiast.
  • 🔍 My research interests include OSS poisoning, model exposure abuse, malicious packages, and DevSecOps automation.

🛠️ Open Source Contributions

I believe in giving back to the community and actively contribute to key open source security projects:


🎤 Conference Talks & Arsenal

I have presented my research and tools at several top-tier security conferences, including:

Black Hat USA 2025 Black Hat Asia 2025 Black Hat Europe 2024 DEF CON 32 AppSec Village DC 2025


📊 GitHub Stats & Achievements

Streak Stats

Top Languages

GitHub Trophies


📌 Featured Project: SCAGoat

A deliberately insecure and compromised SCA testbed that simulates:

  • CVE exposure in Node.js and Spring Boot apps
  • Malicious/compromised packages
  • Reachability and fix validation workflows
    Ideal for evaluating SCA tools, container scanners, and CI/CD defenses.

Profile Views

💬 Let’s connect to talk about research, secure development, OSS risks, or collaborations!

Pinned Loading

  1. Damn-vulnerable-sca Damn-vulnerable-sca Public

    Damn Vulnerable SCA Application

    Java 39 40

  2. depcheck depcheck Public

    A CLI tool to identify SCA security vulnerabilities in packages and provide suggestions for upgrade versions, breaking changes, CVSS and advisories.

    Go 1

  3. flowlyt flowlyt Public

    Flowlyt is a security analyzer that scans GitHub Actions workflows to detect malicious patterns, misconfigurations, and secrets exposure, helping enforce secure CI/CD practices.

    Go 11 4

  4. scs-feed scs-feed Public

    Aggregates and updates supply chain security blog posts daily using GitHub Actions (runs every day at 00:00 UTC).

    JavaScript 1

  5. combat-sca combat-sca Public

    Python