267 packages matching “cwe-772”
safe-inflight
v2.0.0 · 1 month ago
Security fork of [email protected] with the CWE-772 memory leak fixed: queued callbacks are no longer dropped when one throws, and the in-flight entry is always released. Version 2.x deliberately sits ABOVE upstream's highest published version (1.0.6) so SCA
No known vulnerabilities
cwe-sdk
v1.1.19 · 1 year ago
A Common Weakness Enumeration (CWE) Node.js SDK compliant with MITRE / CAPEC
No known vulnerabilities
@strixgov/tool-gateway
v0.5.0 · 1 month ago
Local-first governed tool execution gateway for AI agents. Read/write classification, policy evaluation, signed execution receipts, multi-key rotation with cross-signed chain snapshots, per-capability rate limits, threshold-based escalation, file/webhook
No known vulnerabilities
@aeriajs/security
v0.0.305 · 3 months ago
This package implements common security checks. The checks can be used separatelly, or through a function called `useSecurity()`. This function returns an object with two functions:
No known vulnerabilities
@security-alert/sarif-to-markdown
v1.11.1 · 8 months ago
Convert Sarif format to body text
No known vulnerabilities
cognium-dev
v4.9.24 · 15 hours ago
Static Application Security Testing CLI for detecting security vulnerabilities via taint tracking
No known vulnerabilities
fetch-cwe-list
v0.1.2 · 24 days ago
A simple Node.js module that fetches and parses the latest Common Weakness Enumeration (CWE) list
No known vulnerabilities
oauthlint-rules
v0.11.1 · 28 days ago
Semgrep rules catching the OAuth, OIDC, JWT, and MCP security bugs that AI coding tools produce.
No known vulnerabilities
fetch-cwe-list-mcp
v0.1.0 · 24 days ago
MCP (Model Context Protocol) server exposing fetch-cwe-list tools for LLM agents. Experimental/alpha — APIs may change.
No known vulnerabilities
form-data-to-object
v0.2.1 · 1 month ago
Converts application/x-www-form-urlencoded keys to plain JS object
No known vulnerabilities
@clovnet/plugin-cli
v0.2.3 · 14 days ago
Clovnet plugin developer CLI — create, dev-loop (hot reload + live logs), lifecycle-test and publish plugins against a Clovnet runtime.
No known vulnerabilities
@oxpulse/intro-protocol
v0.2.4 · 1 month ago
L2 introduction protocol — Briar-faithful intro crypto (X25519+HKDF+AEAD), JSON+Zod wire codec, and Signal-style safety numbers. Fixes CWE-208 timing oracle in sessionId redundancy check. EXPERIMENTAL (0.1.0).
No known vulnerabilities
snyk-to-html
v3.7.9 · 1 month ago
Convert JSON output from `snyk test --json` into a static HTML report
No known vulnerabilities
@microsoft/sarif
v5.7.0 · 27 days ago
SARIF SDK for Node.js: open-typed object model, region/snippet resolution, AI ruleId convention, and serialization helpers. Native TypeScript; no CLR dependency.
No known vulnerabilities
@oxpulse/crypto-primitives
v0.5.1 · 1 month ago
Pairwise X25519+HKDF+AEAD primitives, XChaCha20-Poly1305, PQXDH hybrid KEM, MessageEnvelope v2 codec (authenticated binding transcript), and timing-safe comparison helpers for oxpulse-chat.
No known vulnerabilities
cwe-tool
v1.4.2 · 2 years ago
A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.
No known vulnerabilities
crypto-ld
v7.0.0 · 4 years ago
A Javascript library for generating and performing common operations on Linked Data cryptographic key pairs.
No known vulnerabilities
create-clovnet-plugin
v0.2.1 · 14 days ago
Scaffold a Clovnet plugin — thin alias for `clovnet-plugin create` (use via `pnpm create clovnet-plugin <name>`).
No known vulnerabilities
tslint-angular-security
v0.0.5 · 7 years ago
Angular security rules for TSLint
No known vulnerabilities
breakcurl
v0.2.0 · 24 days ago
Security-focused negative API testing from one working cURL
No known vulnerabilities