panki27 / npm-manifest-check
Check NPM packages for manifest confusion
☆44Updated last year
Alternatives and similar repositories for npm-manifest-check:
Users that are interested in npm-manifest-check are comparing it to the libraries listed below
- An open-source collection of API key rotation tutorials.☆67Updated this week
- ☆54Updated 10 months ago
- An Open Letter to the OWASP Board☆106Updated last year
- Scans every git push to your Github organisations to find unwanted secrets.☆88Updated last year
- Vulnerable by Design AWS Cloud Development Kit (CDK) Infrastructure☆46Updated last year
- A project to visualize the software supply chain☆40Updated last year
- Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows☆83Updated 2 weeks ago
- HashiCorp-relevant rules for the Semgrep code analysis tool☆39Updated last year
- A tool for quickly evaluating IAM permissions in AWS.☆72Updated 9 months ago
- YouShallNotPass brings an added level of execution security to mission-critical CI/CD Systems.☆36Updated last year
- Mitigate security concerns of Dependency Confusion supply chain security risks☆46Updated 2 years ago
- ☆12Updated 4 months ago
- ☆47Updated 2 years ago
- EZGHSA is a command-line tool for summarizing and filtering vulnerability alerts on Github repositories.☆35Updated 3 months ago
- Compare vulnerability scanners results (to make them better!)☆16Updated this week
- A guide on coordinated vulnerability disclosure for open source projects. Includes templates for security policies (security.md) and disc…☆119Updated 2 months ago
- Semgrep-based Policy Controller for Kubernetes☆47Updated last week
- Security tool against dependency typosquatting attacks☆39Updated this week
- boostsecurityio/poutine☆259Updated 3 weeks ago
- An IAM Simulator that outputs detailed explains of how a request was evaluated.☆74Updated 3 weeks ago
- The source files and tools needed to build the OWASP Cornucopia decks in various languages☆61Updated this week
- ☆32Updated 7 months ago
- Holds the public Hacking the Cloud CTFs.☆55Updated last year
- Documentation of Semgrep: a fast, open-source, static analysis tool.☆40Updated this week
- Tools that checks for misconfigured access to Github OIDC from AWS roles and GCP service accounts☆61Updated last year
- This terraform provider can be used to get remote code execution by injecting a dummy resource in a writeable state file.☆53Updated last month
- Interrogate your GitHub resources with the help of the world's greatest detectives: Powerpipe + Steampipe + Sherlock.☆39Updated 5 months ago
- A multifaceted security tool which leverages Public GitHub REST APIs for OSINT, Forensics, Pentesting and more.☆134Updated 3 weeks ago
- Tool for obfuscating and deobfuscating data.☆69Updated last year
- Sample code for finding AWS Account ID of an S3 bucket.☆50Updated last year