snyk / vulncostLinks
Find security vulnerabilities in open source npm packages while you code
☆206Updated 3 years ago
Alternatives and similar repositories for vulncost
Users that are interested in vulncost are comparing it to the libraries listed below
Sorting:
- Collection of security best practices for package managers.☆162Updated 2 years ago
- ESLint plugin to detect and stop Trojan Source attacks☆77Updated 2 years ago
- 🛕 Reuse GitHub Actions workflows across repositories☆265Updated 4 years ago
- Custom ESLint rule to disallows unsafe innerHTML, outerHTML, insertAdjacentHTML and alike☆238Updated 3 weeks ago
- Security advisories for Node.js and the JavaScript ecosystem.☆41Updated 4 years ago
- proxy designed to reduce the attack surface of npm publish☆116Updated last month
- Tracking framework performance and usage at scale☆153Updated 8 months ago
- Detect trojan source attacks that employ unicode bidi attacks to inject malicious code☆47Updated 2 years ago
- A Common Weakness Enumeration (CWE) Node.js SDK compliant with MITRE / CAPEC☆32Updated 4 months ago
- TSLint security rules☆69Updated 4 years ago
- Fast and simple way to check any HTTP Headers☆46Updated last year
- ☆49Updated 2 weeks ago
- Detect what kind of CI environment the program is in☆53Updated 2 years ago
- A developer-friendly secrets detection tool for CI and pre-commit hooks based on Yelp's detect-secrets☆51Updated 3 years ago
- ☆39Updated 4 years ago
- ESLint security plugin for Node.js☆103Updated last year
- A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.☆57Updated this week
- NodeJS runtime protection for supply chain attacks☆141Updated 2 years ago
- Audits an NPM package.json file to identify known vulnerabilities.☆227Updated 6 months ago
- Deadshot is a Github pull request scanner to identify sensitive data being committed to a repository☆191Updated 7 months ago
- Detect vulnerable regexes in your project. REDOS, catastrophic backtracking.☆329Updated 3 years ago
- ☆191Updated 7 months ago
- UUID V4☆63Updated 2 years ago
- Run multiple open source security static analysis tools without the added complexity with OSSAR (Open Source Static Analysis Runner).☆96Updated last year
- Scans every git push to your Github organisations to find unwanted secrets.☆87Updated last month
- Helps you understand and work through npm audit results☆19Updated 2 years ago
- ☆243Updated 3 weeks ago
- ☆132Updated 2 weeks ago
- Create a Content-Security-Policy for a website based on the statically detectable relations☆76Updated last week
- `timers/promises` for client and server.☆18Updated 3 years ago