Node.js security advisories
nodesecurity.io
nodesecurity.io
I really wish other projects had something like that (rubygems, pypi, etc.)
cd() {
builtin cd $*
if [ -f "package.json" ] ; then
npm check-vulnerabilities
fi
}
I reckon you could also use this with david[0] to check if packages are up to date.Honest question, have you ever seen a public Javascript security advisory?
No.
>> Shouldn't we start with JavaScript security advisories
Its a language, not a specific implementation of a language. Chromes javascript engine is what would have security vulnerabilities, no javascript itself.
This isn't security advisories for node itself, it is for node modules. the node security project is auditing all of the modules in npm for security issues, and posting about them there.
It's not even that, it's a dialect of ECMAScript.