sonatype-nexus-community / auditjs
Audits an NPM package.json file to identify known vulnerabilities.
☆227Updated 5 months ago
Alternatives and similar repositories for auditjs:
Users that are interested in auditjs are comparing it to the libraries listed below
- creates CycloneDX Software-Bill-of-Materials (SBOM) from node-based projects☆127Updated 2 months ago
- TSLint security rules☆70Updated 4 years ago
- Find security vulnerabilities in open source npm packages while you code☆205Updated 3 years ago
- njsscan is a semantic aware SAST tool that can find insecure code patterns in your Node.js applications.☆398Updated 5 months ago
- ☆49Updated this week
- Detect vulnerable regexes in your project. REDOS, catastrophic backtracking.☆327Updated 3 years ago
- Some thoughts on how Node.js might respond to a changing security environment☆173Updated 6 years ago
- Create CycloneDX Software Bill of Materials (SBOM) from Node.js NPM projects.☆85Updated 2 weeks ago
- Software Component Verification Standard (SCVS)☆143Updated 3 weeks ago
- A minimal port of the old, publicly archived "owasp-esapi-js" (Enterprise Security API for JavaScript) encoder.☆136Updated 2 years ago
- SonarQube Scanner for the JavaScript world☆176Updated 2 years ago
- Scan your code for security misconfiguration, search for passwords and secrets.☆644Updated last year
- Custom ESLint rule to disallows unsafe innerHTML, outerHTML, insertAdjacentHTML and alike☆236Updated 5 months ago
- ☆39Updated 2 years ago
- A unified DevSecOps Framework that allows you to go from iterative, collaborative Threat Modeling to Application Security Test Orchestrat…☆279Updated 3 weeks ago
- Zap baseline scanner in Docker with authentication☆103Updated 11 months ago
- OWASP Foundation Web Repository☆47Updated 3 months ago
- Node application to help managing Maturity Models like the ones created by BSIMM and OpenSAMM☆193Updated 6 years ago
- Fully open-source SAST scanner supporting a range of languages and frameworks. Integrates with major CI pipelines and IDE such as Azure D…☆148Updated 4 years ago
- The ZAP Heads Up Display (HUD)☆263Updated 2 months ago
- Fuzz testing for HTTP APIs with Artillery.io 🌪☆60Updated 2 years ago
- Security design pattern support for Node.js☆24Updated 5 years ago
- A project security/vulnerability/risk scanning tool☆361Updated 3 years ago
- OWASP Foundation Threat Dragon Project Web Repository☆79Updated last week
- An application to assist in the organization and prioritization of software security activities.☆139Updated 3 years ago
- CLI component of OWASP PurpleTeam☆128Updated last year
- Orchestron is an Application Vulnerability Management and Correlation Tool.Orchestron helps you solve one key problem "Find and fix vulne…☆31Updated 2 years ago
- The OWASP ZAP Jenkins Plugin extends the functionality of the ZAP security tool into a CI Environment.☆60Updated 6 months ago
- Repo to hold mapping of user-security-stories☆120Updated 6 years ago
- An open source, online threat modelling tool from OWASP☆483Updated 9 months ago