donald-pinckney / npm-follower
☆15Updated last year
Alternatives and similar repositories for npm-follower:
Users that are interested in npm-follower are comparing it to the libraries listed below
- get popular npm packages☆35Updated 8 months ago
- Coverage-guided, in-process fuzzing for Node.js☆292Updated 7 months ago
- Generate a Snyk dependency tree from package-lock.json or yarn.lock file☆63Updated this week
- Construct approximate static call graph for JavaScript & Typescript☆186Updated 2 years ago
- Instrumentation framework for Node.js compliant to ECMAScript 2020 based on GraalVM.☆53Updated last week
- Performant taint analysis for Node.js☆49Updated 5 months ago
- Client libraries for AppMap☆51Updated this week
- SARIF Microsoft Visual Studio Code extension☆113Updated 3 months ago
- Artifact accompanying our ICSE '22 paper "Practical Automated Detection of Malicious npm Packages"☆42Updated 3 years ago
- 🌍 Normalized repository URLs for every package in the npm registry. Updated daily.☆81Updated this week
- Towards Measuring Supply Chain Attacks on Package Managers for Interpreted Languages☆127Updated 2 years ago
- UI fuzz testing in headless chromium. Let a monkey with a typewriter augment your QA process.☆12Updated 10 months ago
- A delta debugger for JavaScript☆51Updated 2 years ago
- ODGen is a JavaScript Static Analysis tool to detect multiple types of vulnerabilities in Node.js packages.☆151Updated last year
- Public version of CNEPS☆20Updated last month
- ☆29Updated 3 months ago
- Query the npm registry for metadata, package documents, manifests, download counts and other data.☆31Updated last week
- A reimplementation of LastPyMile: A Python-based library to Identify the differences between build artifacts of PyPI packages and the res…☆15Updated 3 years ago
- Creates a CFG from JavaScript source code.☆68Updated 4 months ago
- ☆10Updated 3 months ago
- A dataset of software supply chain compromises. Please help us maintain it!☆127Updated 2 years ago
- This repository contains a list of papers about software supply chain☆26Updated 8 months ago
- The OpenSSF CVE Benchmark consists of code and metadata for over 200 real life CVEs, as well as tooling to analyze the vulnerable codebas…☆141Updated 10 months ago
- A simple chatbot built with XState.☆17Updated 2 years ago
- ☆54Updated last year
- A C/C++ dependency scanner☆38Updated last year
- 📼 Simplest high speed testing☆25Updated 3 weeks ago
- JavaScript/TypeScript static analyzer for call graph construction, library usage pattern matching, and vulnerability exposure analysis☆345Updated last month
- A large dataset of real-world WebAssembly binaries, collected from the Web, GitHub, NPM and other sources. Useful as test data, to study …☆56Updated 2 years ago
- JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns 🔬.☆230Updated 3 weeks ago