LavaMoat / LavaDomeLinks
Secure DOM trees isolation and encapsulation leveraging ShadowDOM
☆36Updated 11 months ago
Alternatives and similar repositories for LavaDome
Users that are interested in LavaDome are comparing it to the libraries listed below
Sorting:
- TC39 proposal for mitigating prototype pollution☆52Updated 2 years ago
- 🌍 Normalized repository URLs for every package in the npm registry. Updated daily.☆96Updated this week
- rewrite constructor arguments, call DOMPurify, profit☆72Updated last year
- 🔤 A list of all the public package names on npm. Updated daily.☆289Updated this week
- Use Snow to finally secure your web app's same origin realms!☆115Updated 10 months ago
- DOM Clobbering Wiki, Browser Testing, and Payload Generation☆60Updated last month
- Custom ESLint rule to disallows unsafe innerHTML, outerHTML, insertAdjacentHTML and alike☆240Updated 5 months ago
- Concurrent prettier runner☆263Updated last year
- JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns 🔬.☆268Updated last week
- The trustworthy ReDoS checker☆289Updated this week
- Find XS-Leaks in the browser by diffing DOM-Graphs in two states☆18Updated last year
- ☆142Updated last month
- List of Trusted Types bypasses☆102Updated last year
- Beyond XSS: Explore the Web Front-end Security Universe. A series about front-end security☆173Updated 3 months ago
- This proposal introduces a new magic comment that signals to browsers that the functions in a JavaScript file are likely to be needed by …☆49Updated 6 months ago
- ☆261Updated last week
- ☆144Updated last month
- Explainer for the PEPC feature☆59Updated last week
- Idiosyncracies of the HTML parser☆41Updated last year
- Collection of security best practices for package managers.☆164Updated 3 years ago
- XS-Leaks Wiki☆175Updated 8 months ago
- A collection of client-side libraries with HTML injection vulnerabilities and DOM clobbering gadgets.☆47Updated 5 months ago
- Explainer for AbortSignal.any(), a new DOM API that enables combining AbortSignals☆26Updated 3 years ago
- Proposal to migrate cleanup some to its own proposal repository☆18Updated 3 years ago
- ☆12Updated 11 months ago
- A CLI and library which tests helps score how vulnerable a regex pattern is to ReDoS attacks. Supported in the browser, Node and Deno.☆52Updated this week
- ☆38Updated 4 months ago
- Discussing standardizing serverless JS functions☆25Updated last year
- Companion labs to "An Exploration of JSON Interoperability Vulnerabilities"☆212Updated 2 years ago
- ☆29Updated last week