The Node.js Bug Bounty Program is a program managed through the HackerOne platform, aiming to identify and fix security vulnerabilities in the Node.js ecosystem. The program is led by a team of experts, including @fraxken, @marco-ippolito, @mdawson, @RafaelGSS, and @ulisesGascon, with the goal of making Node.js a more secure platform. The program is currently working on several initiatives, including the Permission Model, Automating Security Release Process, and Assessment against best practices. For more information, please visit the program's page on HackerOne.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
Amass by OWASP performs comprehensive attack surface mapping and asset discovery.
A vulnerability scanner that helps you identify and fix vulnerabilities in your code
A vulnerability and exposure management platform that unifies security tool data, automates workflows, and provides risk-based prioritization for enterprise vulnerability management programs.
Automate software supply chain security by blocking malicious open source components
SecurityVulnerability.io simplifies the process of collecting, enriching, and presenting vulnerability information for both human and machine consumption.
A demonstration site for the Acunetix Web Vulnerability Scanner, featuring intentionally vulnerable PHP code to test web application security.
Automate OSINT for threat intelligence and attack surface mapping with SpiderFoot.
A collection of real-world scenarios to evaluate command injection detection and exploitation abilities
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.