Giter Club home page Giter Club logo

eslint-security's Introduction

ESLint Configuration for Security Source Code Reviews or DevSecOps

For security source code reviews I don't care about missing newlines etc. What I do care about is the output of ESLint security plugins. With the file contained in this repository, ESLint turns into a little SAST tool for JavaScript applications.

The config file is highly inspired by Greenwolfs eslint-security-scanner-configs.

Prerequisites

Make sure you have ESLint installed globally: npm i -g eslint

For some reason it isn't possible to install eslint plugins globally so they have to be installed locally in the eslint-security directory:

npm i --save-dev eslint-plugin-standard eslint-plugin-import eslint-plugin-node eslint-plugin-promise eslint-config-standard eslint-config-semistandard eslint-plugin-scanjs-rules eslint-plugin-no-unsanitized eslint-plugin-prototype-pollution-security-rules eslint-plugin-angularjs-security-rules eslint-plugin-react eslint-plugin-security eslint-plugin-no-wildcard-postmessage eslint-plugin-html eslint-plugin-no-secrets eslint-plugin-security-node

Execute ESLint with the Config File

  • Make sure that in the directory you want to execute ESLint in there is no .eslintrc.* file.
  • Make sure that no important rules are explicitly ignored in the source code (search for eslint-disable).
eslint --ext .html,.htm,.js,.json -c [PATH_TO_ESLINT-SECURITY]/default.js [PATH_TO_REPO_TO_TEST]

Utilized Security Plugins

Known Issues

  • When copying the configuration file into the root directory of the code to review, there is an error stating the following: ESLint configuration in [PATH_TO_REPO_TO_TEST]/.eslintrc.js is invalid: - Unexpected top-level property "ignorePatterns". For now, just comment out the ignorePatterns.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.