safely install npm packages by auditing them pre-install stage
-
Updated
Aug 4, 2025 - JavaScript
safely install npm packages by auditing them pre-install stage
njsscan is a semantic aware SAST tool that can find insecure code patterns in your Node.js applications.
Simple tool to scan a website for (DOM-based) XSS vulnerabilities and Open Redirects.
Session Hijacking Visual Exploitation
OWASP SecurityRAT (version 1.x) - Tool for handling security requirements in development
A Tool for Domain Flyovers
Presentations, training modules, and other education materials from Duo Security's Application Security team.
Audit your GitHub Actions workflow runs to see exactly which Actions were downloaded
Additional Resources For Securing The Stack Tutorials
A low-cost approach to testing AI chat experiences and security concepts
Checkmarx Scan Github Action
Zero trust. Zero security. Total exposure. A deliberately vulnerable health tech platform with AI Chatbot for learning about application security and ethical hacking. It contains vulnerabilities from OWASP top 10 Web, API and AI/LLM Security Vulnerabilities. Highly vulnerable, never use in production.
✨ A customizable copilot-instructions.md ruleset & prompts to guide GitHub Copilot toward secure coding defaults in Java, Node.js, C# and Python. Blocks risky patterns, teaches safe habits.
A JavaScript-based SDK for delivering secure browser-based web applications over a Ziti Network
Akamai CLI for Application Security
A simple web app software supply chain monitoring toolkit
Add a description, image, and links to the appsec topic page so that developers can more easily learn about it.
To associate your repository with the appsec topic, visit your repo's landing page and select "manage topics."