lunasec-io / damn-vulnerable-js-sca
An intentionally vulnerable Javascript app containing notable vulnerabilities in its dependencies.
โ19Updated 2 years ago
Alternatives and similar repositories for damn-vulnerable-js-sca
Users that are interested in damn-vulnerable-js-sca are comparing it to the libraries listed below
Sorting:
- Manager of third-party sources of Semgrep rules ๐โ82Updated 9 months ago
- ๐งช Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.โ39Updated 5 months ago
- boostsecurityio/lotpโ125Updated last month
- โ66Updated this week
- โ110Updated last year
- Unauthenticated enumeration of AWS IAM Roles.โ25Updated 4 months ago
- Simple Command Line Tool to Enumerate Slack Workspace Names from Slack Webhook URLs.โ41Updated last year
- Security tool against dependency typosquatting attacksโ39Updated last week
- A project to visualize the software supply chainโ50Updated last year
- HashiCorp-relevant rules for the Semgrep code analysis toolโ41Updated last year
- Semgrep-based Policy Controller for Kubernetesโ47Updated last month
- PII detection platform, leveraging human-in-the-loop AIโ52Updated 5 months ago
- Demonstrates how a malicious dependency could negatively impact the build output.โ26Updated last year
- ๐A cutting edge context aware GraphQL API fuzzing tool!โ140Updated 3 weeks ago
- Proof-of-concept code for research into GitHub Actions Cache poisoning.โ21Updated 2 months ago
- Nuclei plugins to audit Chrome extensionsโ64Updated 9 months ago
- Container Blackbox Security Auditing Tool: enumerates security configuration from within the target containerโ106Updated 6 years ago
- Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive filesโ218Updated 3 weeks ago
- Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflowsโ110Updated this week
- โ30Updated 3 years ago
- An implementation of infrastructure-as-code scanning using dynamic tooling.โ56Updated 3 years ago
- โ17Updated 3 years ago
- A comprehensive checklist and guide for organizations looking to implement a robust cybersecurity programโ27Updated this week
- Create notes during a security code review in VSCode ๐ Import your favorite SAST tool findings ๐ ๏ธ and collaborate with others ๐คโ133Updated last month
- An Open Letter to the OWASP Boardโ106Updated last year
- PESD (Proxy Enriched Sequence Diagrams) Exporter converts Burp Suite's proxy traffic into interactive diagramsโ104Updated 3 months ago
- Example repository for GitHub Actions Time of Check to Time of Use (TOCTOU vulnerabilities)โ23Updated last week
- a hackbot proof-of-conceptโ39Updated last year
- ๐๏ธ STRIDE vs. ASVS equivalence tableโ76Updated 8 months ago
- A web CTF for training developers in bug hunting and secure coding!โ99Updated 4 months ago