spaceraccoon / npm-zoo
A zoo for malicious NPM packages
☆20Updated last year
Related projects ⓘ
Alternatives and complementary repositories for npm-zoo
- Security advisories for Node.js and the JavaScript ecosystem.☆41Updated 3 years ago
- Make it easy to probe the strengths and weaknesses of a hardened Node.js stack☆19Updated 5 years ago
- A Common Weakness Enumeration (CWE) Node.js SDK compliant with MITRE / CAPEC☆33Updated 3 weeks ago
- ☆12Updated last year
- ESLint plugin with rules for finding security issues in React projects.☆18Updated 3 years ago
- Policy management tool for Node.js☆22Updated last year
- Hands-on practical use of HTTP security headers as browser security controls to help secure web applications☆18Updated last year
- Visualize your project security vulnerabilities as a pie chart in the terminal☆24Updated last year
- A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.☆55Updated 2 months ago
- Module to prevent SSRF when sending requests in NodeJS. Blocks request to local and private IP addresses☆22Updated 3 months ago
- A tool for detecting regular expression denial-of-service vulnerabilities in Android apps.☆33Updated 8 years ago
- Discussion area for security aspects of ECMAScript☆64Updated 6 years ago
- A developer-friendly secrets detection tool for CI and pre-commit hooks based on Yelp's detect-secrets☆49Updated 2 years ago
- A Node.js middleware for Express that implements Security.txt - A Method for Web Security Policies☆18Updated 2 years ago
- Derive property based testing fast-check into a fuzzer for REST APIs☆38Updated 3 years ago
- 🌍 Normalized repository URLs for every package in the npm registry. Updated daily.☆78Updated this week
- Problem statement and basic mitigations for ephemeral fingerprinting on the web.☆20Updated 3 years ago
- Programmatically fetch security vulnerabilities with one or many strategies (NPM Audit, Sonatype, Snyk, Node.js DB).☆30Updated 2 weeks ago
- Vulnerabilities discovered in npm packages [Berkeley PL & Security Research]☆42Updated 4 months ago
- ☆16Updated 6 years ago
- Inject JS to the DOM to find vulnerable JavaScript libraries☆10Updated last month
- Use `npx aud` instead of `npm audit`, whether you have a lockfile or not!☆26Updated 3 months ago
- Mitigate security concerns of Dependency Confusion supply chain security risks☆40Updated 2 years ago
- Snyk Node Runtime Agent☆16Updated 2 years ago
- List of sensitive fields that should be masked, obfuscated, or purged for security purposes☆20Updated last year
- Day to day relevant info about Operational Security for Nodejs projects