google / safe-html-types
Security contract types
☆60Updated 2 years ago
Alternatives and similar repositories for safe-html-types:
Users that are interested in safe-html-types are comparing it to the libraries listed below
- This is both a terrible and wonderful idea.☆11Updated 5 years ago
- A Modest Content Security Proposal☆40Updated 3 years ago
- Secure Contexts, but with _more_ secureness!☆20Updated 9 months ago
- Security Crawl Maze is a comprehensive testbed for web security crawlers. It contains pages representing many ways in which one can link …☆157Updated last year
- Parse Content Security Policy headers, warn about policy errors, safely manipulate, render, and optimise policies☆72Updated 5 months ago
- WebAppSec Content Security Policy☆215Updated 2 weeks ago
- Discussion area for security aspects of ECMAScript☆64Updated 7 years ago
- Externalize Java application access to protected resources as log messages.☆40Updated 9 months ago
- Custom ESLint rule to disallows unsafe innerHTML, outerHTML, insertAdjacentHTML and alike☆234Updated 3 months ago
- Identify vulnerable libraries in Maven dependencies☆46Updated 2 years ago
- Security advisories for Node.js and the JavaScript ecosystem.☆41Updated 3 years ago
- ☆145Updated 2 years ago
- Cookies should take scheme into account, just like every other storage mechanism on the web.☆16Updated 4 years ago
- A documentation and tracking project with the goal of making package management systems more secure.☆50Updated 3 years ago
- Explainer for Schemeful Same-Site☆15Updated 4 years ago
- DEPRECATED - web security checklist for Firefox Services☆74Updated 4 years ago
- Serial Whitelist Application Trainer☆29Updated 5 years ago
- A dashboard for interesting DOM tricks/techniques.☆36Updated 4 years ago
- Fetch Metadata☆75Updated last week
- A fuzzing library in JavaScript. ✨☆117Updated 4 months ago
- A tool for detecting regular expression denial-of-service vulnerabilities in Android apps.☆33Updated 8 years ago
- Static analysis tool for javascript code based. Scanjs uses Esprima to convert sources to AST, then walks AST looking for patterns.☆54Updated 10 years ago
- `document.domain` intentionally weakens the only security boundary we have. Perhaps we can dump it?☆16Updated last year
- A tiny Java agent that blocks attacks against unsafe deserialization☆83Updated 7 years ago
- CVE database store☆130Updated 4 years ago
- Static Program Analysis for Reliable Trusted Apps☆22Updated 6 years ago
- Maven central doesn't do SSL when serving you JARs. Dilettante is a MiTM proxy for exploiting that.☆160Updated 2 weeks ago
- Java Agent which mitigates deserialisation attacks by making certain classes unserializable☆189Updated 8 years ago
- Go static analysis tool that checks for security issues using an AST.☆28Updated 6 years ago
- ☆52Updated 8 months ago