RetireJS's profile picture. Free open source scanner for detecting use of JavaScript libraries with known vulnerabilities

retire.js

@RetireJS

Free open source scanner for detecting use of JavaScript libraries with known vulnerabilities

retire.js a reposté

Finally! Prime Time for the Salesforce Code Analyser This security checker wraps and harmonizes proven Open-Source like @pmd_analyzer, @geteslint, and @RetireJS. To bring them on par with commercial offerings Salesforce added a flexible Data Flow engine. developer.salesforce.com/blogs/2022/10/…


retire.js a reposté

The nodejs scanner part of retire.js is now deprecated. Will try to keep the frontend javascript scanner working, but with npm audit having so much higher quality, deprecating the node bit seems like the most responsible choice: github.com/RetireJS/retir…


npm 6 is pretty awesome! This is output from npm install

RetireJS's tweet image. npm 6 is pretty awesome! This is output from npm install

npm 6 will have built-in dependency auditing! This is great! It also means we will most likely deprecate the node.js scanning capability of retire.js and focus on client side libraries only. github.com/npm/npm/releas…


retire.js a reposté

Retire.js made the front page news today here in Norway. Lots of govt web sites using vulnerable #js libs: nrk.no/dokumentar/off…


retire.js a reposté

Hey #JavaScript developers. Using moment.js? We've plugged a potential security hole. Please update to 2.11.2. Thanks!


"Top15 security predictions 2016 Ghosts of Internet Past ...old and broken JS versions that invite compromise..." infoworld.com/article/301595…


Current record from a scan: 6 different versions of jQuery loaded on the same page


retire.js a reposté

Go check your site for vulnerable JS libs here: retire.insecurity.today #siksym15


retire.js a reposté

Retire.js ile Javascript Kütüphanelerinizin Güvenliğini Kontrol Edin devnot.com/2015/retire-js…


Could really use help in going through release notes of these WYSIWYG editors to look for vulnerabilities: github.com/RetireJS/retir… #js


retire.js a reposté

Well played @TeslaMotors well played.

marcwrogers's tweet image. Well played @TeslaMotors well played.

retire.js a reposté

Important security release for Node.js v0.12 will be available shortly, please upgrade. v0.10.x is not impacted. Sorry for the short notice.


Loading...

Something went wrong.


Something went wrong.