ossf / package-manager-best-practicesLinks
Collection of security best practices for package managers.
☆164Updated 3 years ago
Alternatives and similar repositories for package-manager-best-practices
Users that are interested in package-manager-best-practices are comparing it to the libraries listed below
Sorting:
- ☆140Updated last week
- ESLint plugin to detect and stop Trojan Source attacks☆79Updated last month
- Find security vulnerabilities in open source npm packages while you code☆211Updated 3 years ago
- Create CycloneDX Software Bill of Materials (SBOM) from Node.js NPM projects.☆115Updated last week
- ☆138Updated last week
- Custom ESLint rule to disallows unsafe innerHTML, outerHTML, insertAdjacentHTML and alike☆239Updated 3 months ago
- GitHub action to generate a CycloneDX SBOM for Node.js☆22Updated 5 months ago
- Hands-on practical use of HTTP security headers as browser security controls to help secure web applications☆18Updated 2 years ago
- ☆48Updated 3 months ago
- creates CycloneDX Software-Bill-of-Materials (SBOM) from node-based projects☆135Updated last month
- JavaScript code and supporting files for working with the 'Static Analysis Results Interchange Format' (SARIF, see https://github.com/oas…☆31Updated last year
- ESLint Plugin focused on common security issues and misconfigurations.☆49Updated 10 months ago
- A developer-friendly secrets detection tool for CI and pre-commit hooks based on Yelp's detect-secrets☆52Updated 3 years ago
- Code-signing for npm packages☆175Updated last week
- Do you have a boatload of speaking gigs? Use this CLI to manage them all!☆35Updated 3 years ago
- proxy designed to reduce the attack surface of npm publish☆120Updated last week
- Orchestrate GitHub Actions Security☆303Updated 2 weeks ago
- A CLI tool to find out if your dependencies support a given version of node.☆104Updated 2 years ago
- Security advisories for Node.js and the JavaScript ecosystem.☆40Updated 4 years ago
- Node 18's node:test, as an npm package☆97Updated last year
- ☆18Updated last month
- ESLint security plugin for Node.js☆106Updated last year
- Bundles of multiple resources, to improve loading JS and the Web.☆106Updated 2 years ago
- get popular npm packages☆42Updated 9 months ago
- rewrite constructor arguments, call DOMPurify, profit☆71Updated last year
- Programmatically fetch security vulnerabilities with one or many strategies (NPM Audit, Sonatype, Snyk, Node.js DB).☆30Updated last week
- A Webpack plugin for generating Web Bundles output.☆63Updated last month
- TSLint security rules☆69Updated 5 years ago
- JavaScript security CLI that allow you to deeply analyze the dependency tree of a given package or local Node.js project.☆379Updated this week
- ☆259Updated last month