Audits JavaScript projects using the OSS Index v3 REST API to identify known vulnerabilities and outdated package versions. Supports any project with package managers that install npm dependencies into a node_modules folder including: npm, Angular, yarn, bower. For users wanting to use Nexus IQ Server as their data source for scanning, version 77 or above must be installed. The user performing the scan must have the permission 'Can Evaluate Applications', which can be found in the Role Editor > User > Permissions > IQ Installation. AuditJS can be used via npx (least permanent install) or global install (most permanent install). It supports node LTS versions of 8.x forward at the moment.
FEATURES
ALTERNATIVES
iOS application for testing iOS penetration testing skills in a legal environment.
A community effort to compile security advisories for Ruby libraries with a detailed directory structure.
Scans Alpine base images for vulnerabilities using Multi Stage builds in Docker 17.05
A hybrid mobile app for Android that intentionally contains vulnerabilities for testing and education
A tool for static analysis of known vulnerabilities, trojans, viruses, malware & other malicious threats in docker images/containers
Advanced vulnerability assessment tool for gaining visibility and preventing cyber attacks.
PINNED

InfoSecHired
An AI-powered career platform that automates the creation of cybersecurity job application materials and provides company-specific insights for job seekers.

Mandos Brief Newsletter
A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.

System Two Security
An AI-powered platform that automates threat hunting and analysis by processing cyber threat intelligence and generating customized hunt packages for SOC teams.

Aikido Security
Aikido is an all-in-one security platform that combines multiple security scanning and management functions for cloud-native applications and infrastructure.

Permiso
Permiso is an Identity Threat Detection and Response platform that provides comprehensive visibility and protection for identities across multiple cloud environments.

Wiz
Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.

Adversa AI
Adversa AI is a cybersecurity company that provides solutions for securing and hardening machine learning, artificial intelligence, and large language models against adversarial attacks, privacy issues, and safety incidents across various industries.