LavaMoat / LavaDomeLinks
Secure DOM trees isolation and encapsulation leveraging ShadowDOM
☆36Updated 9 months ago
Alternatives and similar repositories for LavaDome
Users that are interested in LavaDome are comparing it to the libraries listed below
Sorting:
- TC39 proposal for mitigating prototype pollution☆52Updated 2 years ago
- 🌍 Normalized repository URLs for every package in the npm registry. Updated daily.☆94Updated this week
- Use Snow to finally secure your web app's same origin realms!☆115Updated 8 months ago
- JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns 🔬.☆260Updated last week
- rewrite constructor arguments, call DOMPurify, profit☆71Updated last year
- Find XS-Leaks in the browser by diffing DOM-Graphs in two states☆16Updated 10 months ago
- 🔤 A list of all the public package names on npm. Updated daily.☆285Updated this week
- List of Trusted Types bypasses☆102Updated last year
- Coverage-guided, in-process fuzzing for Node.js☆321Updated 3 weeks ago
- Custom ESLint rule to disallows unsafe innerHTML, outerHTML, insertAdjacentHTML and alike☆237Updated 3 months ago
- Concurrent prettier runner☆255Updated last year
- Mitigate security concerns of Dependency Confusion supply chain security risks☆50Updated 5 months ago
- DOM Clobbering Wiki, Browser Testing, and Payload Generation☆58Updated 7 months ago
- Collection of security best practices for package managers.☆164Updated 3 years ago
- ☆140Updated 3 weeks ago
- A CLI and library which tests helps score how vulnerable a regex pattern is to ReDoS attacks. Supported in the browser, Node and Deno.☆52Updated this week
- ☆47Updated 4 months ago
- A proposal to partition :visited link history by top-level site and frame origin.☆59Updated 6 months ago
- Companion labs to "An Exploration of JSON Interoperability Vulnerabilities"☆210Updated 2 years ago
- Beyond XSS: Explore the Web Front-end Security Universe. A series about front-end security☆166Updated last month
- XS-Leaks Wiki☆169Updated 6 months ago
- Prototype Pollution in JavaScript☆75Updated 3 years ago
- Awesome MXSS ??☆55Updated last year
- Explainer for AbortSignal.any(), a new DOM API that enables combining AbortSignals☆26Updated 3 years ago
- This proposal introduces a new magic comment that signals to browsers that the functions in a JavaScript file are likely to be needed by …☆50Updated 3 months ago
- HTML Universal Identifier☆65Updated 11 months ago
- ☆26Updated last week
- ☆143Updated last week
- A curated list of awesome browser security learning material.☆145Updated 3 years ago
- Explainer for the PEPC feature☆53Updated last week