Node.js Security Profile
Node.js Security

@nodesecurity

Followers
11K
Following
143
Media
40
Statuses
776

Security team at @npmjs tweeting about JavaScript security.

Oakland, CA
Joined February 2013
Don't wanna be here? Send us removal request.
@nodesecurity
Node.js Security
8 years
The Node Security Platform is joining @npmjs https://t.co/3qSqp7K5Aj
2
15
30
@nodesecurity
Node.js Security
5 years
Automating Vulnerable Dependency Checking in CI Using Open Source by @varrunr https://t.co/hY4D6fjny5
0
0
5
@npmjs
npm
6 years
it’s official! we’re now a part of @github. excited for the next chapter of npm: https://t.co/j19Tv3VLsI
22
429
2K
@npmjs
npm
6 years
Big news! We’re excited to announce that @npmjs will be joining @GitHub! We're thrilled to join an organization as committed to open source as we are, so that the npm registry can remain free & public forever. You can read more about this new chapter here: https://t.co/xjInDE46io
50
1K
3K
@ronperris
Ron Perris
6 years
Going live at 9AM PT! Will be talking about JavaScript ecosystem security and solutions you can get involved in.
@absoluteappsec
Absolute AppSec
6 years
We’re live at noon EST / 9am PST with our very special guest @ronperris 😎! Feel free to ask questions on the YT live chat, in Slack (link on https://t.co/hxhFuGOFez) or email us at absoluteappsec@gmail.com. https://t.co/5p7RICiSxU
0
3
9
@nodesecurity
Node.js Security
6 years
Did you ever want to know how a pentester makes their way from bug to exploit? Read about how @truesec found and exploited a bug in hot-formula-parser (CVE-2020-6836) https://t.co/vopwYujwBF
1
2
9
@nodesecurity
Node.js Security
6 years
Please update your npm cli to v6.13.4 as soon as you can. npm i npm -g https://t.co/jVRZdRXqU9
8
103
123
@nodesecurity
Node.js Security
6 years
Great writeup about a remote code execution (RCE) vulnerability in the Strapi framework and the quick response by the Strapi team.
bittherapy.net
CVE: CVE-2019-19609 Vendor: Strapi (https://strapi.io) Product: Strapi Framework Version Affected: strapi-3.0.0-beta.17.7 and earlier Fix PR: https://github.com/strapi/strapi/pull/4636 NPM Advisory:...
0
2
2
@npmjs
npm
6 years
the npm security team has been hard at work building infrastructure to do behavioral analysis of npm packages at scale. vp of security, @adam_baldwin, explains what this entails (+ a sneak peek at the security insights API): https://t.co/cjgDSgIwTx
0
6
10
@nodesecurity
Node.js Security
6 years
This Node.js Best Practices guide by @nodepractices has some great security guidance. https://t.co/q1omG4DC38
0
13
40
@eleuterio_
André Eleuterio
6 years
We get a lot of requests from people wanting to do research around malware in the Registry. It will be really exciting to see what the community does with this data!
@npmjs
npm
6 years
for years, npm has maintained the most complete corpus of malware published on the npm registry. learn more about the malware corpus by the numbers & what to look for in our security insights api: https://t.co/BQhROw7gsM
0
2
9
@nodesecurity
Node.js Security
6 years
Did you miss us? Well we're back and tweeting. The npm security team has taken over the nodesecurity twitter account and will be keeping you up to date on JavaScript security related happenings.
0
9
38
@DailySwig
The Daily Swig
6 years
The Daily Swig speaks to npm’s @adam_baldwin about improving security for the world’s biggest repository of open source software packages https://t.co/2xi6QEJmUn
portswigger.net
PortSwigger offers tools for web application security, testing, & scanning. Choose from a range of security tools, & identify the very latest vulnerabilities.
0
3
8
@nodesecurity
Node.js Security
7 years
The Node Security Platform Service is shutting down tomorrow: https://t.co/F6ThtOVI61
1
4
2
@nodesecurity
Node.js Security
7 years
On 9/30 the Node Security Platform will stop working. Here’s what you can do: https://t.co/F6ThtOVI61
0
0
1
@nodesecurity
Node.js Security
7 years
The Node Security Platform is shutting down on 9/30:
0
2
3
@nodesecurity
Node.js Security
7 years
JavaScript’s definitive listing of known package vulnerabilities is moving to @npmjs Here’s how to use it: https://t.co/F6ThtOVI61
0
7
5
@nodesecurity
Node.js Security
7 years
HashWick - a new vulnerability found by @indutny - impacts all v8js releases.
0
4
9
@nodesecurity
Node.js Security
7 years
Are you prepared to move on from the Node Security Platform service? Here’s what you can do: https://t.co/F6ThtOVI61
0
2
2