wspr-ncsu / mininodeLinks
Mininode is a CLI tool to reduce the attack surface of the Node.js applications by using static analysis.
β21Updated 2 years ago
Alternatives and similar repositories for mininode
Users that are interested in mininode are comparing it to the libraries listed below
Sorting:
- An HTTP Response fuzzer to find Vulnerabilities in Security Scannersβ27Updated last year
- Manager of 14 third-party sources comprising approximately 4,000 Semgrep rules πβ98Updated last month
- Dependency Combobulatorβ95Updated 2 years ago
- Mitigate security concerns of Dependency Confusion supply chain security risksβ51Updated 3 weeks ago
- Testability Pattern Catalogs for SASTβ31Updated 11 months ago
- Run CodeQL queries at scale using Multi-Repository Variant Analysis (MRVA)β61Updated 9 months ago
- The OpenSSF CVE Benchmark consists of code and metadata for over 200 real life CVEs, as well as tooling to analyze the vulnerable codebasβ¦β160Updated last year
- Source code for ACM CCS 2020 Paper PMForce: Systematically Analyzing postMessage Handlers at Scaleβ18Updated 4 years ago
- Kubernetes Pwnage for allβ57Updated 5 years ago
- JAW: A Graph-based Security Analysis Framework for Client-side JavaScriptβ117Updated 4 months ago
- A collection of Semgrep rules which followed security guidelines for .NET and Java.β23Updated 4 years ago
- β25Updated last year
- A Simple command line tool that helps checking web applications to identify insecure deserialization vulnerabilities.β24Updated 6 years ago
- Generic SAST Libraryβ135Updated 7 months ago
- OpenAPI 2.0 (Swagger) fuzzer written in python. Basically TnT for your API.β111Updated 3 years ago
- Dockerfile for AFL++ and helpful other toolsβ21Updated 5 years ago
- β52Updated last year
- A collection of my Semgrep rulesβ51Updated 2 years ago
- Scan pypi for typosquattingβ38Updated 3 years ago
- A Python3 module to assist in fuzzing web applicationsβ57Updated 2 years ago
- Reference architecture and proof of concept implementation for supply chain security gatewayβ23Updated 2 years ago
- β44Updated 4 years ago
- An extension to use Semgrep inside Burp Suite.β89Updated 8 months ago
- Documentation of Semgrep: a fast, open-source, static analysis tool.β48Updated this week
- A regular expression fuzzer.β45Updated 7 years ago
- TaintFlow, a framework for JavaScript dynamic information flow analysis.β18Updated 3 years ago
- HTTP Desync Attackβ28Updated 5 years ago
- A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.β62Updated 8 months ago
- Static Token And Credential Scannerβ95Updated 2 years ago
- A full example reportβ11Updated 6 years ago