Audits JavaScript projects using the OSS Index v3 REST API to identify known vulnerabilities and outdated package versions. Supports any project with package managers that install npm dependencies into a node_modules folder including: npm, Angular, yarn, bower. For users wanting to use Nexus IQ Server as their data source for scanning, version 77 or above must be installed. The user performing the scan must have the permission 'Can Evaluate Applications', which can be found in the Role Editor > User > Permissions > IQ Installation. AuditJS can be used via npx (least permanent install) or global install (most permanent install). It supports node LTS versions of 8.x forward at the moment.
FEATURES
ALTERNATIVES
Automate software supply chain security by blocking malicious open source components
A script that checks for common best-practices around deploying Docker containers in production.
A small script to check a list of domains against open redirect vulnerability
A comprehensive online resource for application security knowledge
Cloud-based service for testing and analyzing Android and iOS apps for malware, vulnerabilities, and security threats.
Donate to your favorite open-source projects and charities using PayPal
A comprehensive database of exploits and vulnerabilities for researchers and professionals
PINNED
InfoSecHired
An AI-powered career platform that automates the creation of cybersecurity job application materials and provides company-specific insights for job seekers.
Fabric Platform by BlackStork
Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.
Mandos Brief Newsletter
Stay ahead in cybersecurity. Get the week's top cybersecurity news and insights in 8 minutes or less.
Wiz
Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.
RoboShadow
A cybersecurity platform that offers vulnerability scanning, Windows Defender and 3rd party AV management, and MFA compliance reporting, among other features.
Adversa AI
Adversa AI is a cybersecurity company that provides solutions for securing and hardening machine learning, artificial intelligence, and large language models against adversarial attacks, privacy issues, and safety incidents across various industries.