{"repo":"ajinabraham/njsscan","free":true,"listed":false,"github":"https://github.com/ajinabraham/njsscan","clone":"git clone https://github.com/ajinabraham/njsscan.git","description":"njsscan is a semantic aware SAST tool that can find insecure code patterns in your Node.js applications.","language":"JavaScript","stars":449,"topics":["nodejs","expressjs","sast","staticanalysis","devsecops","codescanner","linter","security","security-tools","semantic"],"license":"LGPL-3.0","category":"security-tools","readme_excerpt":"njsscan njsscan is a static application testing (SAST) tool that can find insecure code patterns in your node.js applications using simple pattern matcher from libsast and syntax-aware semantic code pattern search tool semgrep. Made with in India Support njsscan Donate via Paypal: Sponsor the Project: e-Learning Courses & Certifications OpSecX Node.js Security: Pentesting and Exploitation - NJS Installation pip install njsscan Requires Python 3.10+ and supports only Mac and Linux Command Line Options Example Usage nodejsscan SAST nodejsscan , built on top of njsscan provides a full fledged vulnerability management user interface along with other nifty integrations. See nodejsscan Python API Configure njsscan A .njsscan file in the root of the source code directory allows you to configure njsscan. You can also use a custom .njsscan file using --config argument. Suppress Findings You can suppress findings from javascript source files by adding the comment // njsscan-ignore: rule id1, rule id2 to the line that trigger the findings. Example: CI/CD Integrations You can enable njsscan in your CI/CD or DevSecOps pipelines. Github Action Add the following to the file .github/workflows/njsscan.yml . Example: dvna with njsscan github action Github Code Scanning Integration Add the following to the file .github/workflows/njsscan sarif.yml . Gitlab CI/CD Add the following to the file .gitlab-ci.yml . Example command (local): This writes a native GitLab SAST report so findings appear in t","default_branch":null,"files":null,"tree":[],"storefront":"/r/ajinabraham","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/ajinabraham/njsscan/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}