Skip to content

Test code with insecure dependencies and SonarQube vulnerabilities

Notifications You must be signed in to change notification settings

thirdender/flaming-security-mistake

Repository files navigation

Flaming Security Mistake

This repo includes many security mistakes that should be discovered by SAST tools.

  • package-lock.json includes Node packages with known vulnerabilities
  • Gemfile.lock includes dependencies that are listed as insecure in the ruby-advisory-db
  • index.js includes code meant to trigger the SonarJS vulnerability rules

About

Test code with insecure dependencies and SonarQube vulnerabilities

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published