snyk / vulncost
Find security vulnerabilities in open source npm packages while you code
☆202Updated 2 years ago
Related projects ⓘ
Alternatives and complementary repositories for vulncost
- Collection of security best practices for package managers.☆159Updated 2 years ago
- Custom ESLint rule to disallows unsafe innerHTML, outerHTML, insertAdjacentHTML and alike☆231Updated this week
- TSLint security rules☆70Updated 4 years ago
- Detect vulnerable regexes in your project. REDOS, catastrophic backtracking.☆320Updated 2 years ago
- Audits an NPM package.json file to identify known vulnerabilities.☆223Updated last week
- Security advisories for Node.js and the JavaScript ecosystem.☆41Updated 3 years ago
- A developer-friendly secrets detection tool for CI and pre-commit hooks based on Yelp's detect-secrets☆49Updated 2 years ago
- Hands-on practical use of HTTP security headers as browser security controls to help secure web applications☆18Updated last year
- ESLint plugin to detect and stop Trojan Source attacks☆76Updated last year
- Fast and simple way to check any HTTP Headers☆45Updated last year
- ☆189Updated last month
- ☆128Updated last week
- A Common Weakness Enumeration (CWE) Node.js SDK compliant with MITRE / CAPEC☆33Updated 3 weeks ago
- JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns 🔬.☆229Updated 2 weeks ago
- Some thoughts on how Node.js might respond to a changing security environment☆172Updated 5 years ago
- njsscan is a semantic aware SAST tool that can find insecure code patterns in your Node.js applications.☆375Updated last week
- ☆330Updated 3 weeks ago
- Do you have a boatload of speaking gigs? Use this CLI to manage them all!☆34Updated 2 years ago
- ☆228Updated 2 months ago
- Concurrent prettier runner☆205Updated 5 months ago
- An eslint plugin to find strings that might be secrets/credentials☆137Updated 2 weeks ago
- NodeJS runtime protection for supply chain attacks☆142Updated 2 years ago
- ☆39Updated 4 years ago
- ☆46Updated last week
- Mitigate security concerns of Dependency Confusion supply chain security risks☆40Updated 2 years ago
- A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.☆55Updated 2 months ago
- Detect what kind of CI environment the program is in☆53Updated last year
- JavaScript code and supporting files for working with the 'Static Analysis Results Interchange Format' (SARIF, see https://github.com/oas…☆27Updated 5 months ago
- Detect trojan source attacks that employ unicode bidi attacks to inject malicious code☆47Updated last year
- Run multiple open source security static analysis tools without the added complexity with OSSAR (Open Source Static Analysis Runner).☆95Updated 7 months ago