Skip to content
@NodeSecure

NodeSecure

A group of people 👯 moving toward a safer Node.js and JavaScript ecosystem 🐢🚀

👋 Welcome visitor

We are building free open source tools to secure the Node.js & JavaScript ecosystem. Our biggest area of expertise is in package and code analysis (SCA).

We are mainly developers who like to build tools that bring you value for free ❤️. Our tools often provide a range of benefits and information such as:

  • Non opinionated metrics (On quality and maintainability).
  • Very useful information about the projects you use:
    • OpenSSF Scorecard.
    • SPDX license conformance.
    • Vulnerabilities (with support of multiple strategies: NPM, Sonatype, Snyk).
  • The different security threats within your codes (detected using our open source SAST JS-X-Ray).

Our tools have proven to be of great use to rigorous developers and package maintainers. But there is still a long way to go to make our tools more accessible to beginners 💪.

❤️ Contributors

We welcome new contributors. Please feel free to join us on Discord and help on the different projects.

OpenAlly

It doesn't necessarily matter if you are a beginner in security or not. Many projects require skills that are not directly related to security. So don't feel illegitimate to come and contribute and learn.

🐤 How to contribute

Learn how you can contribute by reading our guide:

Resources to learn more about the project or good security practices

Contribution Guidelines

Before contributing, please check and read our Code of conduct. There is some guides available to help developers and contributors:

👥 Open Alliance

The maintainers of NodeSecure are also the creators behind projects like TopCli, Dashlog, and many more (see OpenAlly).

Pinned Loading

  1. Governance Governance Public

    NodeSecure Governance (Code of conduct & Contribution guidelines)

    HTML 14 4

  2. cli cli Public

    JavaScript security CLI that allow you to deeply analyze the dependency tree of a given package or local Node.js project.

    JavaScript 375 43

  3. js-x-ray js-x-ray Public

    JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns 🔬.

    TypeScript 253 29

  4. scanner scanner Public

    ⚡️ A package API to run a static analysis of your module's dependencies. This is the CLI engine!

    TypeScript 35 19

  5. vulnera vulnera Public

    Programmatically fetch security vulnerabilities with one or many strategies (NPM Audit, Sonatype, Snyk, Node.js DB).

    TypeScript 30 13

  6. report report Public

    NodeSecure HTML & PDF report generator for any public and/or private git repositories.

    JavaScript 14 13

Repositories

Showing 10 of 34 repositories
  • js-x-ray Public

    JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns 🔬.

    NodeSecure/js-x-ray’s past year of commit activity
    TypeScript 253 MIT 29 8 (5 issues need help) 2 Updated Jul 17, 2025
  • scanner Public

    ⚡️ A package API to run a static analysis of your module's dependencies. This is the CLI engine!

    NodeSecure/scanner’s past year of commit activity
    TypeScript 35 MIT 19 9 (3 issues need help) 4 Updated Jul 16, 2025
  • cli Public

    JavaScript security CLI that allow you to deeply analyze the dependency tree of a given package or local Node.js project.

    NodeSecure/cli’s past year of commit activity
    JavaScript 375 MIT 43 7 (3 issues need help) 3 Updated Jul 14, 2025
  • landing Public

    NodeSecure landing page

    NodeSecure/landing’s past year of commit activity
    HTML 1 MIT 0 3 (1 issue needs help) 1 Updated Jul 14, 2025
  • Governance Public

    NodeSecure Governance (Code of conduct & Contribution guidelines)

    NodeSecure/Governance’s past year of commit activity
    HTML 14 MIT 4 2 0 Updated Jul 13, 2025
  • vulnera Public

    Programmatically fetch security vulnerabilities with one or many strategies (NPM Audit, Sonatype, Snyk, Node.js DB).

    NodeSecure/vulnera’s past year of commit activity
    TypeScript 30 MIT 13 5 (2 issues need help) 3 Updated Jul 7, 2025
  • report Public

    NodeSecure HTML & PDF report generator for any public and/or private git repositories.

    NodeSecure/report’s past year of commit activity
    JavaScript 14 MIT 13 1 (1 issue needs help) 0 Updated Jul 1, 2025
  • ci Public

    NodeSecure tool enabling secured continuous integration

    NodeSecure/ci’s past year of commit activity
    TypeScript 21 MIT 10 2 3 Updated Jul 1, 2025
  • ossf-scorecard-sdk Public

    Node.js SDK for OpenSSF scorecard

    NodeSecure/ossf-scorecard-sdk’s past year of commit activity
    TypeScript 6 MIT 4 0 0 Updated Jul 1, 2025
  • flags Public

    NodeSecure security flags 🚩 (configuration and documentation)

    NodeSecure/flags’s past year of commit activity
    HTML 2 MIT 8 0 0 Updated Jul 1, 2025