ossf / package-manager-best-practicesLinks
Collection of security best practices for package managers.
☆164Updated 3 years ago
Alternatives and similar repositories for package-manager-best-practices
Users that are interested in package-manager-best-practices are comparing it to the libraries listed below
Sorting:
- ☆141Updated last week
- ESLint plugin to detect and stop Trojan Source attacks☆79Updated 2 months ago
- Find security vulnerabilities in open source npm packages while you code☆211Updated 3 years ago
- JavaScript code and supporting files for working with the 'Static Analysis Results Interchange Format' (SARIF, see https://github.com/oas…☆31Updated last year
- GitHub action to generate a CycloneDX SBOM for Node.js☆22Updated 6 months ago
- ESLint Plugin focused on common security issues and misconfigurations.☆52Updated 11 months ago
- Code-signing for npm packages☆178Updated last week
- ☆140Updated last week
- ☆260Updated last month
- Hands-on practical use of HTTP security headers as browser security controls to help secure web applications☆19Updated 3 years ago
- ☆48Updated 4 months ago
- Orchestrate GitHub Actions Security☆303Updated this week
- JavaScript package.json License Checker☆181Updated last year
- A CLI tool to find out if your dependencies support a given version of node.☆103Updated 2 years ago
- The goal of this project is to provide additional features on top of the existing npm audit options☆131Updated 2 months ago
- Create CycloneDX Software Bill of Materials (SBOM) from Node.js NPM projects.☆116Updated last week
- creates CycloneDX Software-Bill-of-Materials (SBOM) from node-based projects☆136Updated last month
- Configurable linter for package.json files☆251Updated this week
- ESLint security plugin for Node.js☆106Updated last year
- JavaScript implementation of The Update Framework (TUF)☆82Updated last week
- Detect Glassworm & trojan source attacks that employ unicode bidi attacks to inject malicious code☆57Updated 2 months ago
- [GitHub] A Command Line ToolKit for GitHub Security Alert.☆28Updated last week
- Do you have a boatload of speaking gigs? Use this CLI to manage them all!☆35Updated 3 years ago
- Lint an npm or yarn lockfile to analyze and detect security issues☆837Updated 8 months ago
- GitHub token permissions Monitor and Advisor actions☆350Updated last month
- proxy designed to reduce the attack surface of npm publish☆120Updated last week
- Bundles of multiple resources, to improve loading JS and the Web.☆106Updated 2 years ago
- URL Pattern Standard☆187Updated last month
- Programmatically fetch security vulnerabilities with one or many strategies (NPM Audit, Sonatype, Snyk, Node.js DB).☆30Updated 2 weeks ago
- Get a list of licenses used by a projects dependencies☆19Updated 2 years ago