Linking pages
- Nodejs Security - OWASP Cheat Sheet Series https://cheatsheetseries.owasp.org/cheatsheets/Nodejs_Security_Cheat_Sheet.html 45 comments
- GitHub - selfrefactor/useful-javascript-libraries: Collection of Javascript libraries https://github.com/selfrefactor/useful-javascript-libraries 9 comments
- GitHub - guardrailsio/awesome-php-security: Awesome PHP Security Resources 🕶🐘🔐 https://github.com/guardrailsio/awesome-php-security 0 comments
- How to generate an SBOM for JavaScript and Node.js applications | Snyk https://snyk.io/blog/generate-sbom-javascript-node-js-applications/ 0 comments
- Using insecure npm package manager defaults to steal your macOS keyboard shortcuts | Snyk https://snyk.io/blog/using-insecure-npm-package-manager-defaults/ 0 comments
Linked pages
- I don't know what to say. · Issue #116 · dominictarr/event-stream · GitHub https://github.com/dominictarr/event-stream/issues/116 1396 comments
- Security issue: compromised npm packages of ua-parser-js (0.7.29, 0.8.0, 1.0.0) - Questions about deprecated npm package ua-parser-js · Issue #536 · faisalman/ua-parser-js · GitHub https://github.com/faisalman/ua-parser-js/issues/536 1159 comments
- left-pad.io http://left-pad.io/ 720 comments
- Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other Companies | by Alex Birsan | Medium https://medium.com/@alex.birsan/dependency-confusion-4a5d60fec610 661 comments
- Popular 'coa' NPM library hijacked to steal user passwords https://www.bleepingcomputer.com/news/security/popular-coa-npm-library-hijacked-to-steal-user-passwords/ 616 comments
- incolumitas.com – Typosquatting programming language package managers http://incolumitas.com/2016/06/08/typosquatting-package-managers/ 602 comments
- Virus in eslint-scope? · Issue #39 · eslint/eslint-scope · GitHub https://github.com/eslint/eslint-scope/issues/39 557 comments
- Andrew Sampson on Twitter: "Earlier this year, npm indefinitely suspended their process for “adopting an abandoned package” (wiping all references to it from their documentation.) That was because of me. A thread 🧵 1/?" / Twitter https://twitter.com/andrewmd5/status/1423915732979437571?s=21 470 comments
- Alert: peacenotwar module sabotages npm developers in the node-ipc package to protest the invasion of Ukraine | Snyk https://snyk.io/blog/peacenotwar-malicious-npm-node-ipc-package-vulnerability/ 405 comments
- How one developer just broke Node, Babel and thousands of projects in 11 lines of JavaScript • The Register https://www.theregister.co.uk/2016/03/23/npm_left_pad_chaos/ 382 comments
- Postmortem for Malicious Packages Published on July 12th, 2018 - ESLint - Pluggable JavaScript Linter https://eslint.org/blog/2018/07/postmortem-for-malicious-package-publishes 326 comments
- Creative Commons — CC0 1.0 Universal http://creativecommons.org/publicdomain/zero/1.0/ 305 comments
- Somebody Tried to Hide a Backdoor in a Popular JavaScript npm Package https://www.bleepingcomputer.com/news/security/somebody-tried-to-hide-a-backdoor-in-a-popular-javascript-npm-package/ 292 comments
- NPM registry prank leaves developers unable to unpublish packages | SC Media https://www.scmagazine.com/news/npm-registry-prank-leaves-developers-unable-to-unpublish-packages 276 comments
- https://schneid.io/blog/event-stream-vulnerability-explained/ 233 comments
- is-promise post mortem. Last Saturday, I made the decision to… | by Forbes Lindesay | JavaScript in Plain English https://medium.com/@forbeslindesay/is-promise-post-mortem-cab807f18dcc 222 comments
- npm Blog Archive: Plot to steal cryptocurrency foiled by the npm security team https://blog.npmjs.org/post/185397814280/plot-to-steal-cryptocurrency-foiled-by-the-npm 213 comments
- npm Blog Archive: Reported malicious module: getcookies https://blog.npmjs.org/post/173526807575/reported-malicious-module-getcookies 185 comments
- Malicious npm package opens backdoors on programmers' computers | ZDNET https://www.zdnet.com/article/malicious-npm-package-opens-backdoors-on-programmers-computers/ 178 comments
- Sabotage: Code added to popular NPM package wiped files in Russia and Belarus | Ars Technica https://arstechnica.com/information-technology/2022/03/sabotage-code-added-to-popular-npm-package-wiped-files-in-russia-and-belarus/ 176 comments
Related searches:
Search whole site: site:github.com
Search title: GitHub - lirantal/awesome-nodejs-security: Awesome Node.js Security resources
See how to search.