Skip to content
@NodeSecure

NodeSecure

A group of people 👯 moving toward a safer Node.js and JavaScript ecosystem 🐢🚀

👋 Welcome visitor

We are building free open source tools to secure the Node.js & JavaScript ecosystem. Our biggest area of expertise is in package and code analysis.

We are mainly developers who like to build tools that bring you value for free ❤️. Our tools often provide a range of benefits and information such as:

  • Non opinionated metrics (On quality and maintainability).
  • Very useful information about the projects you use:
    • OpenSSF Scorecard.
    • SPDX license conformance.
    • Vulnerabilities (with support of multiple strategies: NPM, Sonatype, Snyk).
  • The different security threats within your codes (detected using our open source SAST JS-X-Ray).

Our tools have proven to be of great use to rigorous developers and package maintainers. But there is still a long way to go to make our tools more accessible to beginners 💪.

❤️ Contributors

We welcome new contributors. Please feel free to join us on Discord and help on the different projects.

ES-Community

It doesn't necessarily matter if you are a beginner in security or not. Many projects require skills that are not directly related to security. So don't feel illegitimate to come and contribute and learn.

🐤 How to contribute

Learn how you can contribute by reading our guide:

Resources to learn more about the project or good security practices

Pinned

  1. Governance Public

    NodeSecure Governance (Code of conduct & Contribution guidelines)

    8 2

  2. cli Public

    JavaScript security CLI that allow you to deeply analyze the dependency tree of a given package or local Node.js project.

    JavaScript 320 32

  3. ci Public

    NodeSecure tool enabling secured continuous integration

    TypeScript 16 4

  4. js-x-ray Public

    JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns 🔬.

    JavaScript 133 14

  5. scanner Public

    ⚡️ A package API to run a static analysis of your module's dependencies.

    JavaScript 17 9

  6. vulnera Public

    Programmatically fetch security vulnerabilities with one or many strategies (NPM Audit, Sonatype, Snyk, Node.js DB).

    JavaScript 20 12

Repositories

Top languages

Loading…

Most used topics

Loading…