npq Logo

npq

0
Free
Visit Website

npq is a tool that safely installs packages with npm/yarn by auditing them as part of your install process. It performs sanity checks to ensure the package is safe to install, including: * Consulting the Snyk.io database of publicly disclosed vulnerabilities * Checking package age on npm * Verifying package download count as a popularity metric * Ensuring the package has a README file * Verifying the package has a LICENSE file * Checking for pre/post install scripts Once installed, npq can be used to safely install packages, such as `npq install express`.

FEATURES

ALTERNATIVES

Tenable One Exposure Management Platform is a comprehensive platform for vulnerability management and exposure management.

Curiefense is an application security platform that protects against various threats and offers community involvement.

A simple, secure framework for building scalable applications

IDAPython plugin for generating Yara rules/patterns from x86/x86-64 code through parameterization.

A centralized application security posture management platform that integrates security tools, automates workflows, and provides visibility into application security risks.

Pint is a PIN tool that exposes the PIN API to lua scripts, allowing dynamic instrumentation of binaries.

Checkmarx One SAST is a static application security testing tool that combines speed and security to improve developer experience.

A software supply chain security platform that analyzes binaries and software components to detect malware, vulnerabilities, exposed secrets, and tampering throughout the development lifecycle.

PINNED