2 ms·
Node.jsScan: A semantic aware static code analysis tool for Node.js applications
- 29athrowaway 6y agohttps://github.com/ajinabraham/njsscan/blob/master/njsscan/rules/semantic_grep/crypto_node.yaml#L5 https://github.com/ajinabraham/njsscan/blob/master/njsscan/r... Does this mean that if I use single quotes or add whitespace inside the parentheses the vulnerability will not be detected?
- danenania 6y agoA quick summary of what exactly this scans for at the top of the README would be nice. From the screenshots at the bottom, it looks like mainly SQL injection and outdated dependencies?
- nailer 6y agoProbably JSON injection too. You can handle this in middleware, but I suspect lot of people don't.
- narrationbox 6y agoStatic analysis software is quite valuable if you can successfully sell it. https://github.blog/2019-09-18-github-welcomes-semmle/ https://github.blog/2019-09-18-github-welcomes-semmle/
- reposhub 6y agohttps://reposhub.com/ajinabraham-nodejsscan-python-code-analysis-and-linter.html https://reposhub.com/ajinabraham-nodejsscan-python-code-anal...