sonatype-nexus-community / auditjs
Audits an NPM package.json file to identify known vulnerabilities.
☆225Updated 2 months ago
Alternatives and similar repositories for auditjs:
Users that are interested in auditjs are comparing it to the libraries listed below
- TSLint security rules☆70Updated 4 years ago
- A minimal port of the old, publicly archived "owasp-esapi-js" (Enterprise Security API for JavaScript) encoder.☆135Updated 2 years ago
- Find security vulnerabilities in open source npm packages while you code☆204Updated 2 years ago
- njsscan is a semantic aware SAST tool that can find insecure code patterns in your Node.js applications.☆383Updated 2 months ago
- Scan your code for security misconfiguration, search for passwords and secrets.☆639Updated last year
- ☆47Updated last month
- creates CycloneDX Software-Bill-of-Materials (SBOM) from node-based projects☆124Updated 2 months ago
- An application to assist in the organization and prioritization of software security activities.☆137Updated 3 years ago
- Fuzz testing for HTTP APIs with Artillery.io 🌪☆60Updated 2 years ago
- Create CycloneDX Software Bill of Materials (SBOM) from Node.js NPM projects.☆77Updated this week
- OWASP Foundation Web Repository☆47Updated 2 weeks ago
- Some thoughts on how Node.js might respond to a changing security environment☆172Updated 5 years ago
- Zap baseline scanner in Docker with authentication☆104Updated 8 months ago
- SAMM stands for Software Assurance Maturity Model.☆398Updated 2 years ago
- Node application to help managing Maturity Models like the ones created by BSIMM and OpenSAMM☆189Updated 6 years ago
- A project security/vulnerability/risk scanning tool☆360Updated 3 years ago
- Custom ESLint rule to disallows unsafe innerHTML, outerHTML, insertAdjacentHTML and alike☆233Updated last month
- SonarQube Scanner for the JavaScript world☆176Updated last year
- Fully open-source SAST scanner supporting a range of languages and frameworks. Integrates with major CI pipelines and IDE such as Azure D…☆147Updated 4 years ago
- Detect vulnerable regexes in your project. REDOS, catastrophic backtracking.☆319Updated 3 years ago
- OWASP Cloud Security - Enabling conversations through threat and control stories☆178Updated 6 years ago
- A unified DevSecOps Framework that allows you to go from iterative, collaborative Threat Modeling to Application Security Test Orchestrat…☆275Updated 3 weeks ago
- ☆57Updated 4 years ago
- threatspec - continuous threat modeling, through code☆340Updated 4 years ago
- A broker system between a public service and a private service☆105Updated this week
- Repo to hold mapping of user-security-stories☆114Updated 6 years ago
- A Continuous Threat Modeling methodology☆313Updated 2 years ago
- Fast and simple way to check any HTTP Headers☆45Updated last year
- OWASP SecurityRAT (version 1.x) - Tool for handling security requirements in development☆175Updated 3 weeks ago
- OWASP Serverless Top 10☆215Updated 3 years ago