ossf / package-manager-best-practicesLinks
Collection of security best practices for package managers.
☆164Updated 3 years ago
Alternatives and similar repositories for package-manager-best-practices
Users that are interested in package-manager-best-practices are comparing it to the libraries listed below
Sorting:
- ESLint plugin to detect and stop Trojan Source attacks☆79Updated last month
- ☆140Updated 3 weeks ago
- GitHub action to generate a CycloneDX SBOM for Node.js☆22Updated 5 months ago
- ☆138Updated last week
- JavaScript code and supporting files for working with the 'Static Analysis Results Interchange Format' (SARIF, see https://github.com/oas…☆30Updated last year
- Find security vulnerabilities in open source npm packages while you code☆211Updated 3 years ago
- Create CycloneDX Software Bill of Materials (SBOM) from Node.js NPM projects.☆109Updated last week
- Code-signing for npm packages☆172Updated this week
- Custom ESLint rule to disallows unsafe innerHTML, outerHTML, insertAdjacentHTML and alike☆237Updated 3 months ago
- ESLint Plugin focused on common security issues and misconfigurations.☆48Updated 9 months ago
- Orchestrate GitHub Actions Security☆301Updated last week
- GitHub token permissions Monitor and Advisor actions☆345Updated 2 weeks ago
- ESLint security plugin for Node.js☆106Updated last year
- creates CycloneDX Software-Bill-of-Materials (SBOM) from node-based projects☆135Updated 2 weeks ago
- ☆48Updated 2 months ago
- proxy designed to reduce the attack surface of npm publish☆119Updated last week
- TC39 proposal for mitigating prototype pollution☆52Updated 2 years ago
- JavaScript security CLI that allow you to deeply analyze the dependency tree of a given package or local Node.js project.☆380Updated this week
- A developer-friendly secrets detection tool for CI and pre-commit hooks based on Yelp's detect-secrets☆52Updated 3 years ago
- Configurable linter for package.json files☆251Updated 2 weeks ago
- Overlay is a browser extension helping developers evaluate open source packages before picking them☆225Updated 5 months ago
- JavaScript package.json License Checker☆181Updated last year
- Hands-on practical use of HTTP security headers as browser security controls to help secure web applications☆18Updated 2 years ago
- Bundles of multiple resources, to improve loading JS and the Web.☆106Updated 2 years ago
- Detect Glassworm & trojan source attacks that employ unicode bidi attacks to inject malicious code☆57Updated 3 weeks ago
- `timers/promises` for client and server.☆18Updated 4 years ago
- ☆254Updated 2 weeks ago
- A CLI tool to find out if your dependencies support a given version of node.☆104Updated 2 years ago
- JavaScript implementation of The Update Framework (TUF)☆82Updated last week
- Library to check if a package is reproducible☆63Updated 2 months ago