lunasec-io / damn-vulnerable-js-scaLinks
An intentionally vulnerable Javascript app containing notable vulnerabilities in its dependencies.
β18Updated 2 years ago
Alternatives and similar repositories for damn-vulnerable-js-sca
Users that are interested in damn-vulnerable-js-sca are comparing it to the libraries listed below
Sorting:
- An Open Letter to the OWASP Boardβ107Updated 2 years ago
- π§ͺ Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.β40Updated 8 months ago
- Unauthenticated enumeration of AWS IAM Roles.β25Updated 7 months ago
- A web fuzzer using the httpipe formatβ101Updated last year
- HashiCorp-relevant rules for the Semgrep code analysis toolβ41Updated last year
- EZGHSA is a command-line tool for summarizing and filtering vulnerability alerts on Github repositories.β35Updated 8 months ago
- Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflowsβ110Updated 3 weeks ago
- A project to visualize the software supply chainβ52Updated last year
- πA cutting edge context aware GraphQL API fuzzing tool!β146Updated last month
- β30Updated 4 years ago
- Semgrep-based Policy Controller for Kubernetesβ47Updated 4 months ago
- β49Updated 2 years ago
- a hackbot proof-of-conceptβ40Updated last year
- image scaling attacks for multi-modal prompt injectionβ56Updated this week
- Example repository for GitHub Actions Time of Check to Time of Use (TOCTOU vulnerabilities)β31Updated 3 months ago
- Vandalize old emails. Like an NFT that's easy to prove ownership of.β35Updated 2 years ago
- Security tool against dependency typosquatting attacksβ53Updated this week
- PII detection platform, leveraging human-in-the-loop AIβ53Updated 8 months ago
- Manager of third-party sources of Semgrep rules πβ87Updated last year
- Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive filesβ220Updated 2 months ago
- A web CTF for training developers in bug hunting and secure coding!β99Updated 7 months ago
- Data about all known supply-chain attacks through historyβ58Updated 2 months ago
- β112Updated 2 years ago
- β71Updated 3 weeks ago
- Pentester-focused Docker registry tool to enumerate and pull imagesβ33Updated 3 weeks ago
- A GitHub Action that creates a SBOM from your application so you can meet compliance and security requirements. Add this to your dev, staβ¦β25Updated 2 years ago
- RedFlag uses AI to identify high-risk code changes. Run it in batch mode for release candidate testing or in CI pipelines to flag PRs andβ¦β152Updated 9 months ago
- boostsecurityio/lotpβ132Updated 4 months ago
- Create notes during a security code review in VSCode π Import your favorite SAST tool findings π οΈ and collaborate with others π€β134Updated 4 months ago
- A lightweight library to sanitize data provided to AI toolsβ28Updated 2 years ago