Collection of npm package manager Security Best Practices
☆1,255May 24, 2026Updated 3 months ago
Alternatives and similar repositories for npm-security-best-practices
Users that are interested in npm-security-best-practices are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- safely install npm packages by auditing them pre-install stage☆1,795Aug 25, 2026Updated 3 weeks ago
- Check your AWS CLI commands for security risks before you run them.☆34Apr 1, 2026Updated 5 months ago
- [Updated for AI 🤖] Continuous updates on how to stay safe from NPM supply chain attacks☆858Aug 24, 2026Updated 3 weeks ago
- ESLint plugin that brings Flow's Render Types to TypeScript via JSDoc. Enforce component composition constraints like `@renders {MenuItem…☆111Jul 18, 2026Updated 2 months ago
- Audit content (pdfs, media files, images) sensitivity on urls☆45Jun 2, 2026Updated 3 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- ✂️ Find unused files, dependencies and exports in your JavaScript and TypeScript projects. Knip it before you ship it!☆12,326Updated this week
- ☆532Aug 19, 2026Updated last month
- A CLI to lint and format MDX content.☆64Aug 28, 2025Updated last year
- This is an incident response playbook we created for the Vercel April 2026 compromise☆32Apr 21, 2026Updated 5 months ago
- The best way to mock JavaScript fetch requests☆199Sep 15, 2026Updated last week
- 🐒 Bundler-free build tool for TypeScript libraries. Powered by tsc.☆1,118Updated this week
- Replace port numbers with stable, named local URLs. For humans and agents.☆12,570Updated this week
- A comprehensive framework for analyzing and defending against attacks targeting Software Development Life Cycle Infrastructure.☆180Jul 29, 2026Updated last month
- 🙅♂️ Catch unnecessary React effects for simpler, faster, safer code.☆1,920Aug 21, 2026Updated last month
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- 25× faster drop-in replacement for `cn`☆1,190Sep 1, 2026Updated 3 weeks ago
- Static analysis for GitHub Actions☆6,555Updated this week
- An ESLint plugin for suggesting optimisations in choice of dependency, native equivalents, etc.☆493Aug 4, 2026Updated last month
- ⚓ A collection of high-performance JavaScript tools.☆22,845Updated this week
- A standard interface for TypeScript schema validation libraries☆3,634Updated this week
- Your agent writes bad React. This catches it☆14,911Updated this week
- Wireit upgrades your npm/pnpm/yarn scripts to make them smarter and more efficient.☆6,425Updated this week
- Unobtrusive logging library with zero dependencies for Deno, Node.js, Bun, browsers, and edge functions☆2,003Updated this week
- My own collection of skills for modern Node.js development☆1,928Aug 17, 2026Updated last month
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- CSS Object Model implemented in pure JavaScript. Also, a CSS parser.☆25Mar 13, 2026Updated 6 months ago
- PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.☆513Updated this week
- Use oxc as a Prettier parser for JavaScript and TypeScript.☆71Jul 19, 2025Updated last year
- `eslint-plugin-import-x` is a fork of `eslint-plugin-import` that aims to provide a more performant and more lightweight version of the o…☆769Updated this week
- A modern JavaScript utility library that's 2-3 times faster and up to 97% smaller, a major upgrade to lodash.☆11,346Updated this week
- ✅ A collection of practical TypeScript patterns that improve safety, readability, maintainability, and developer experience.☆413Aug 17, 2026Updated last month
- The goal of the Package Metadata Interoperability Collab Space is to improve how JavaScript developers define their packages across the e…☆57Mar 2, 2026Updated 6 months ago
- Deepsec is a security harness for finding vulnerabilities in your codebase powered by coding agents☆8,014Sep 16, 2026Updated last week
- Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known softwa…☆5,035Aug 7, 2026Updated last month
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- AI-safe .env files: Schemas for agents, Secrets for humans.☆4,587Updated this week
- Hands-on practical use of HTTP security headers as browser security controls to help secure web applications☆22Jun 14, 2026Updated 3 months ago
- Package any component into a self-contained, isolated widget☆407Apr 13, 2026Updated 5 months ago
- The lightweight, schema-first, and fully type-safe form library for React, Solid, Vue, Svelte and more.☆1,193Updated this week
- Pluggable linting tool to prevent committing credential.☆1,451Updated this week
- Execute TypeScript on Node using SWC☆169Feb 7, 2026Updated 7 months ago
- Install pnpm and a JavaScript runtime (Node.js, Bun, or Deno) in one GitHub actions step☆140Updated this week