panki27 / npm-manifest-check
Check NPM packages for manifest confusion
☆44Updated last year
Alternatives and similar repositories for npm-manifest-check:
Users that are interested in npm-manifest-check are comparing it to the libraries listed below
- Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows☆82Updated last week
- An open-source collection of API key rotation tutorials.☆63Updated 2 months ago
- EZGHSA is a command-line tool for summarizing and filtering vulnerability alerts on Github repositories.☆35Updated last month
- A project to visualize the software supply chain☆39Updated last year
- Recon tool to query cloud prefixes for services associated with an IP address☆24Updated 4 months ago
- Security tool against dependency typosquatting attacks☆39Updated last week
- A guide on coordinated vulnerability disclosure for open source projects. Includes templates for security policies (security.md) and disc…☆119Updated last month
- Too many secrets (2MS) helps people protect their secrets on any file or on systems like CMS, chats and git☆87Updated this week
- A tool to uncover undocumented APIs from the AWS Console.☆95Updated 3 months ago
- An Open Letter to the OWASP Board☆106Updated last year
- Independently deploy customized honeyservices in AWS to trigger alerts on unauthorized access. It utilizes a dedicated CloudTrail for pre…☆48Updated 3 months ago
- A simple touchID prompt'er for use in shell scripts.☆96Updated 8 months ago
- A tool for preventing the installation of malicious PyPI and npm packages☆124Updated this week
- Tool for obfuscating and deobfuscating data.☆67Updated 11 months ago
- This tool analyzes a given Gitlab repository and searches for dangling or force-pushed commits containing potential secret or interesting…☆45Updated 6 months ago
- Holds the public Hacking the Cloud CTFs.☆54Updated 11 months ago
- The OWASP Secure Headers Project☆147Updated this week
- The source files and tools needed to build the OWASP Cornucopia decks in various languages☆57Updated this week
- PII detection platform, leveraging human-in-the-loop AI☆49Updated 2 months ago
- 🧪 Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.☆38Updated 2 months ago
- Analyze any snippet, file, or repository to detect possible security flaws such as secret in code, open source vulnerability, code securi…☆76Updated 6 months ago
- ☆32Updated 6 months ago
- DustiLock is a tool to find which of your dependencies is susceptible to a Dependency Confusion attack.☆35Updated 3 years ago
- AWS STS token decoder☆37Updated 6 months ago
- Semgrep-based Policy Controller for Kubernetes☆46Updated this week
- Stalker, the Extensible Attack Surface Management tool.☆81Updated this week
- A multi-vault secret injection tool for safely injecting secrets into app environment☆116Updated 2 weeks ago
- A GitHub Action to suggest removal of non-organization members from CODEOWNERS files☆124Updated this week
- YouShallNotPass brings an added level of execution security to mission-critical CI/CD Systems.☆36Updated last year