snyk / vulncost
Find security vulnerabilities in open source npm packages while you code
☆205Updated 2 years ago
Alternatives and similar repositories for vulncost:
Users that are interested in vulncost are comparing it to the libraries listed below
- Custom ESLint rule to disallows unsafe innerHTML, outerHTML, insertAdjacentHTML and alike☆235Updated 4 months ago
- Collection of security best practices for package managers.☆162Updated 2 years ago
- Security advisories for Node.js and the JavaScript ecosystem.☆41Updated 3 years ago
- Fast and simple way to check any HTTP Headers☆45Updated last year
- ESLint plugin to detect and stop Trojan Source attacks☆76Updated 2 years ago
- proxy designed to reduce the attack surface of npm publish☆115Updated 2 weeks ago
- A developer-friendly secrets detection tool for CI and pre-commit hooks based on Yelp's detect-secrets☆50Updated 2 years ago
- Audits an NPM package.json file to identify known vulnerabilities.☆227Updated 4 months ago
- 🛕 Reuse GitHub Actions workflows across repositories☆265Updated 4 years ago
- Detect trojan source attacks that employ unicode bidi attacks to inject malicious code☆47Updated 2 years ago
- An extensible, heuristic-based vulnerability scanning tool for installed npm packages☆50Updated 3 years ago
- TSLint security rules☆70Updated 4 years ago
- JavaScript code and supporting files for working with the 'Static Analysis Results Interchange Format' (SARIF, see https://github.com/oas…☆27Updated 10 months ago
- NodeJS runtime protection for supply chain attacks☆141Updated 2 years ago
- ☆190Updated 5 months ago
- Tracking framework performance and usage at scale☆152Updated 6 months ago
- Detect vulnerable regexes in your project. REDOS, catastrophic backtracking.☆321Updated 3 years ago
- ☆49Updated last week
- Get details about the current Continuous Integration environment☆335Updated 3 weeks ago
- A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.☆56Updated 6 months ago
- Detect what kind of CI environment the program is in☆53Updated last year
- Run multiple open source security static analysis tools without the added complexity with OSSAR (Open Source Static Analysis Runner).☆96Updated 11 months ago
- 📦📊 GitHub Action to reports on the size of your npm package☆90Updated last year
- An eslint plugin to find strings that might be secrets/credentials☆145Updated last month
- JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns 🔬.☆238Updated 3 weeks ago
- npm's tree doctor☆371Updated 3 years ago
- ESLint security plugin for Node.js☆103Updated last year
- 🌍 Normalized repository URLs for every package in the npm registry. Updated daily.☆82Updated this week
- JavaScript security CLI that allow you to deeply analyze the dependency tree of a given package or local Node.js project.☆367Updated 3 weeks ago
- Scans every git push to your Github organisations to find unwanted secrets.☆87Updated last year