TypeScript security-tools

Open-source TypeScript projects categorized as security-tools

Top 16 TypeScript security-tool Projects

  • web-check

    πŸ•΅οΈβ€β™‚οΈ All-in-one OSINT tool for analysing any website

  • Project mention: Web-check: All-in-one OSINT tool for analysing any website | news.ycombinator.com | 2024-03-01
  • personal-security-checklist

    πŸ”’ A compiled checklist of 300+ tips for protecting digital security and privacy in 2024

  • Project mention: The Personal Security Checklist | news.ycombinator.com | 2024-02-21

    Checklists at https://github.com/Lissy93/personal-security-checklist/blob/...

  • SurveyJS

    Open-Source JSON Form Builder to Create Dynamic Forms Right in Your App. With SurveyJS form UI libraries, you can build and style forms in a fully-integrated drag & drop form builder, render them in your JS app, and store form submission data in any backend, inc. PHP, ASP.NET Core, and Node.js.

    SurveyJS logo
  • ThreatMapper

    Open source cloud native security observability platform. Linux, K8s, AWS Fargate and more.

  • Project mention: ThreatMapper: Open-source cloud native security observability platform | news.ycombinator.com | 2023-09-10
  • privacy.sexy

    Open-source tool to enforce privacy & security best-practices on Windows, macOS and Linux, because privacy is sexy

  • Project mention: Debloat Windows in 2022 | /r/informatik | 2023-12-11
  • lunasec

    LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and Builds. Protect yourself in 30 seconds with the LunaTrace GitHub App: https://github.com/marketplace/lunatrace-by-lunasec/

  • CloudGraph cli

    The universal GraphQL API and CSPM tool for AWS, Azure, GCP, K8s, and tencent. (by cloudgraphdev)

  • ZeusCloud

    Open Source Cloud Security

  • Project mention: Open-source IAM Access Visualizer | /r/devsecops | 2023-05-17

    It’s part of an open source cloud security platform we’re maintaining. Inspired by discussions with folks in the cloud sec community sharing challenges around assessing blast radius, potential lateral movements, and IAM context around alerts they receive.

  • WorkOS

    The modern identity platform for B2B SaaS. The APIs are flexible and easy-to-use, supporting authentication, user identity, and complex enterprise features like SSO and SCIM provisioning.

    WorkOS logo
  • gradejs

    GradeJS analyzes production Webpack bundles without having access to the source code of a website. Instantly see vulnerabilities, outdated packages, and more just by entering a web application URL.

  • console

    End-to-End encrypted application secrets and configuration management for developers. (by phasehq)

  • Project mention: Phase: HashiCorp Vault and AWS Secrets Manager Alternative for Developers | news.ycombinator.com | 2024-03-24
  • hashpass

    A simple password manager with a twist.

  • jfrog-docker-desktop-extension

    🐸 Scans any of your local Docker images for security vulnerabilities. πŸ‹

  • ots-share-app

    A self-hosting app to share secrets only one-time.

  • npm-lint

    A linter for npm & node package.json files with a focus on dependency security

  • Project mention: JavaScript registry NPM vulnerable to 'manifest confusion' abuse | news.ycombinator.com | 2023-06-27

    That postinstall and other scripts have been a problem for a long time - the PoC for example could be installed via npx, which would then run postinstall which executes another script to steal /etc/password data.

    This is not a new problem, you just have another vector.

    I came up with a free linter package to try solve it - but no one seemed interested, and here we are 7 later talking about where people are now offering paid services to mitigate it.

    https://github.com/tanepiper/npm-lint

  • secutils-webui

    The web user interface for Secutils.dev

  • Project mention: A tiny fix with big impact and high risk | dev.to | 2023-09-19

    The example above shows that you absolutely have to validate all URLs you redirect users to if there is a chance they can be manipulated by third parties. In the Secutils.dev Web UI, specifically, I rely on the native URL class to check if the URL has the proper origin before redirecting the user. Also, check out "Preventing Unvalidated Redirects and Forwards" from OWASP for more tips.

  • ignorecheck

    A simple CLI/utility to ensure certain patterns are present in a project's .gitignore - Be sure to 🌟 this repository for updates!

  • secutils-web-scraper

    The web scrapper component of Secutils.dev

  • Project mention: How to track anything on the internet or use Playwright for fun and profit | dev.to | 2024-01-16

    To begin, all functionality related to browser automation and web scraping lives in a dedicated service β€” Web Scraper. The primary rationale is that dealing with browsers and arbitrary user scripts is tricky from a security standpoint, and it's always a good idea to isolate such functionality as much as possible. You can read more about the security aspects of web scraping in the "Running web scraping service securely" post.

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
NOTE: The open source projects on this list are ordered by number of github stars. The number of mentions indicates repo mentiontions in the last 12 Months or since we started tracking (Dec 2020).

TypeScript security-tools related posts

Index

What are some of the best open-source security-tool projects in TypeScript? This list will help you:

Project Stars
1 web-check 18,864
2 personal-security-checklist 15,680
3 ThreatMapper 4,631
4 privacy.sexy 3,493
5 lunasec 1,406
6 CloudGraph cli 869
7 ZeusCloud 666
8 gradejs 398
9 console 236
10 hashpass 115
11 jfrog-docker-desktop-extension 74
12 ots-share-app 52
13 npm-lint 26
14 secutils-webui 7
15 ignorecheck 4
16 secutils-web-scraper 1

Sponsored
Power Real-Time Data Analytics at Scale
Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.
www.influxdata.com