ossf / package-manager-best-practices
Collection of security best practices for package managers.
☆162Updated 2 years ago
Alternatives and similar repositories for package-manager-best-practices
Users that are interested in package-manager-best-practices are comparing it to the libraries listed below
Sorting:
- Find security vulnerabilities in open source npm packages while you code☆205Updated 3 years ago
- ESLint plugin to detect and stop Trojan Source attacks☆77Updated 2 years ago
- ☆132Updated 2 months ago
- A guide on coordinated vulnerability disclosure for open source projects. Includes templates for security policies (security.md) and disc…☆120Updated 4 months ago
- GitHub token permissions Monitor and Advisor actions☆288Updated last month
- Generate SBOMs with gh CLI☆183Updated 3 weeks ago
- Create CycloneDX Software Bill of Materials (SBOM) from Node.js NPM projects.☆86Updated this week
- Custom ESLint rule to disallows unsafe innerHTML, outerHTML, insertAdjacentHTML and alike☆237Updated this week
- Bundles of multiple resources, to improve loading JS and the Web.☆106Updated last year
- ☆121Updated last week
- Orchestrate GitHub Actions Security☆284Updated this week
- JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns 🔬.☆242Updated this week
- ESLint Plugin focused on common security issues and misconfigurations.☆40Updated 2 months ago
- Code-signing for npm packages☆162Updated this week
- ☆46Updated 8 months ago
- Publish from GitHub Actions using multi-factor authentication☆284Updated last week
- JavaScript code and supporting files for working with the 'Static Analysis Results Interchange Format' (SARIF, see https://github.com/oas…☆28Updated 11 months ago
- Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts☆34Updated 3 months ago
- Our objective is to enable open source maintainers, contributors and end-users to understand and make decisions on the provenance of the …☆182Updated last year
- Overlay is a browser extension helping developers evaluate open source packages before picking them☆224Updated last year
- rewrite constructor arguments, call DOMPurify, profit☆67Updated 7 months ago
- GitHub Actions Goat: Deliberately Vulnerable GitHub Actions CI/CD Environment☆464Updated last month
- creates CycloneDX Software-Bill-of-Materials (SBOM) from node-based projects☆127Updated 3 months ago
- JavaScript implementation of The Update Framework (TUF)☆80Updated last week
- Hands-on practical use of HTTP security headers as browser security controls to help secure web applications☆18Updated 2 years ago
- ☆241Updated last month
- GitHub action to generate a CycloneDX SBOM for Node.js☆21Updated 4 months ago
- A developer-friendly secrets detection tool for CI and pre-commit hooks based on Yelp's detect-secrets☆50Updated 3 years ago
- UUID V4☆63Updated 2 years ago
- A tool to check the security settings of Github Organizations.☆71Updated last year