sonatype-nexus-community / auditjs
Audits an NPM package.json file to identify known vulnerabilities.
☆227Updated 4 months ago
Alternatives and similar repositories for auditjs:
Users that are interested in auditjs are comparing it to the libraries listed below
- creates CycloneDX Software-Bill-of-Materials (SBOM) from node-based projects☆126Updated last month
- TSLint security rules☆70Updated 4 years ago
- ☆49Updated last week
- Fully open-source SAST scanner supporting a range of languages and frameworks. Integrates with major CI pipelines and IDE such as Azure D…☆148Updated 4 years ago
- njsscan is a semantic aware SAST tool that can find insecure code patterns in your Node.js applications.☆393Updated 4 months ago
- Find security vulnerabilities in open source npm packages while you code☆205Updated 2 years ago
- Zap baseline scanner in Docker with authentication☆103Updated 10 months ago
- SAMM stands for Software Assurance Maturity Model.☆398Updated 2 years ago
- Create CycloneDX Software Bill of Materials (SBOM) from Node.js NPM projects.☆82Updated last week
- OWASP Foundation Web Repository☆47Updated 3 months ago
- Software Component Verification Standard (SCVS)☆142Updated 11 months ago
- Scan your code for security misconfiguration, search for passwords and secrets.☆644Updated last year
- The OWASP Secure Headers Project☆153Updated this week
- ☆123Updated last year
- A developer-friendly secrets detection tool for CI and pre-commit hooks based on Yelp's detect-secrets☆50Updated 2 years ago
- Security advisories for Node.js and the JavaScript ecosystem.☆41Updated 3 years ago
- A minimal port of the old, publicly archived "owasp-esapi-js" (Enterprise Security API for JavaScript) encoder.☆136Updated 2 years ago
- Detect vulnerable regexes in your project. REDOS, catastrophic backtracking.☆321Updated 3 years ago
- Some thoughts on how Node.js might respond to a changing security environment☆173Updated 6 years ago
- Custom ESLint rule to disallows unsafe innerHTML, outerHTML, insertAdjacentHTML and alike☆235Updated 4 months ago
- Fuzz testing for HTTP APIs with Artillery.io 🌪☆60Updated 2 years ago
- Make it easy to probe the strengths and weaknesses of a hardened Node.js stack☆19Updated 5 years ago
- Repo to hold mapping of user-security-stories☆118Updated 6 years ago
- An extensible, heuristic-based vulnerability scanning tool for installed npm packages☆50Updated 3 years ago
- Security design pattern support for Node.js☆24Updated 5 years ago
- Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependenci…☆836Updated last year
- A unified DevSecOps Framework that allows you to go from iterative, collaborative Threat Modeling to Application Security Test Orchestrat…☆278Updated this week
- OWASP SecurityRAT (version 1.x) - Tool for handling security requirements in development☆178Updated 3 months ago
- a javascript static security analysis tool☆589Updated 9 years ago
- The DevSecOps toolset for REST APIs☆274Updated 2 years ago