ajinabraham/njsscan
njsscan is a semantic aware SAST tool that can find insecure code patterns in your Node.js applications.
JavaScriptLGPL-3.0
Issues
- 2
Sarif output validation issue on latest release
#125 opened by luke88jones - 3
SARIF output not compliant to specification
#76 opened by StefanFl - 3
- 2
- 2
- 4
False Positive from `.findOne()` using Sequelize
#114 opened by bleow - 13
Getting error while executing njsscan
#95 opened by sumitsharma16 - 1
Issue in njsscan
#109 opened by spmishra121 - 2
Configuration options documentation
#110 opened by luis-guimaraes-exoawk - 3
- 1
node_password false positive
#105 opened by jonny64 - 1
regex_injection_dos false positive
#104 opened by jonny64 - 1
Pin njsscan dependencies
#100 opened by disposedtrolley - 2
Eval backquote Vulnerability not detected
#101 opened by LyesH4ck - 6
Error importing sonarqube report into sonar
#68 opened by kmlp10 - 1
false positive for regex_injection_dos
#96 opened by dogmatic69 - 3
--html no longer works?
#89 opened by erzz - 1
Getting error with -o option, if output path has spaces and special characters in directory name
#88 opened by psandeep09 - 1
future request: Add junit format output
#90 opened by armanbaghajyan - 1
False positives with node_username
#93 opened by snyamathi - 1
Import 3rd party rules
#87 opened by nbeguier - 3
njsscan not running properly on MaC
#91 opened by rohitcoderCdefense - 3
Faulty node_nosqli_injection ??
#83 opened by designamx - 1
export as static html
#86 opened by dberardo-com - 8
SQL injections are no longer detected
#85 opened by ronnn - 0
Rule QA community feedback
#84 opened by ajinabraham - 4
CWE-79 metadata inconsistency
#75 opened by zricethezav - 1
To investigate
#71 opened by ajinabraham - 1
SQLi False positive
#72 opened by ajinabraham - 2
node_username rule overly broad for ERROR
#80 opened by jayvdb - 1
False positive in sql injection rule
#82 opened by wallali - 2
squirrelly_template rule
#81 opened by nbeguier - 1
- 1
angular rules?
#73 opened by javixeneize - 4
false positive for user input?
#78 opened by dogmatic69 - 2
We need new relaese
#74 opened by kadir-taskiran - 2
Replicate Severity filter
#69 opened by ajinabraham - 1
TypeScript support
#66 opened by o8e - 1
- 3
njsscan-ignore in Handlebars template
#63 opened by takemyoxygen - 4
Resource not accessible by integration
#61 opened by aravindvnair99 - 1
change license to lgpl 3
#49 opened by ajinabraham - 6
Something wrong with docker image
#60 opened by melnikaite - 2
[Feature-request] output report as html
#59 opened by a-boulafia - 0
Update rule file name
#56 opened by ajinabraham - 1
njsscan: command not found
#54 opened by slaffcheff - 1
TypeScript support
#57 opened by zakrush - 2
eval trigger
#55 opened by zakrush - 2
- 4