ossf / package-manager-best-practicesLinks
Collection of security best practices for package managers.
☆162Updated 2 years ago
Alternatives and similar repositories for package-manager-best-practices
Users that are interested in package-manager-best-practices are comparing it to the libraries listed below
Sorting:
- ☆133Updated this week
- Custom ESLint rule to disallows unsafe innerHTML, outerHTML, insertAdjacentHTML and alike☆238Updated 2 months ago
- Find security vulnerabilities in open source npm packages while you code☆208Updated 3 years ago
- ESLint plugin to detect and stop Trojan Source attacks☆77Updated 2 years ago
- GitHub action to generate a CycloneDX SBOM for Node.js☆22Updated this week
- JavaScript code and supporting files for working with the 'Static Analysis Results Interchange Format' (SARIF, see https://github.com/oas…☆28Updated last year
- ☆124Updated last week
- Hands-on practical use of HTTP security headers as browser security controls to help secure web applications☆18Updated 2 years ago
- ESLint Plugin focused on common security issues and misconfigurations.☆43Updated 4 months ago
- Create CycloneDX Software Bill of Materials (SBOM) from Node.js NPM projects.☆93Updated this week
- proxy designed to reduce the attack surface of npm publish☆118Updated 2 months ago
- ☆243Updated last week
- ☆46Updated 10 months ago
- Code-signing for npm packages☆165Updated last week
- creates CycloneDX Software-Bill-of-Materials (SBOM) from node-based projects☆129Updated last month
- A guide on coordinated vulnerability disclosure for open source projects. Includes templates for security policies (security.md) and disc…☆122Updated 6 months ago
- Do you have a boatload of speaking gigs? Use this CLI to manage them all!☆35Updated 2 years ago
- JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns 🔬.☆253Updated last week
- ESLint security plugin for Node.js☆104Updated last year
- Programmatically fetch security vulnerabilities with one or many strategies (NPM Audit, Sonatype, Snyk, Node.js DB).☆30Updated last week
- Orchestrate GitHub Actions Security☆291Updated last week
- ☆51Updated 3 weeks ago
- Bundles of multiple resources, to improve loading JS and the Web.☆106Updated last year
- Detect trojan source attacks that employ unicode bidi attacks to inject malicious code☆47Updated 2 years ago
- TC39 proposal for mitigating prototype pollution☆47Updated last year
- Security advisories for Node.js and the JavaScript ecosystem.☆41Updated 4 years ago
- JavaScript security CLI that allow you to deeply analyze the dependency tree of a given package or local Node.js project.☆374Updated this week
- ☆40Updated 5 years ago
- A Common Weakness Enumeration (CWE) Node.js SDK compliant with MITRE / CAPEC☆32Updated 6 months ago
- GitHub token permissions Monitor and Advisor actions☆318Updated last month