Security team at @npmjs tweeting about JavaScript security.

Joined February 2013
40 Photos and videos
Pinned Tweet
The Node Security Platform is joining @npmjs buff.ly/2qgpc8C
2
15
30
Automating Vulnerable Dependency Checking in CI Using Open Source by @varrunr sec.okta.com/articles/2020/0…

5
Node.js Security retweeted
15 Apr 2020
it’s official! we’re now a part of @github. excited for the next chapter of npm: buff.ly/2XQ7fjR
22
424
1,737
Node.js Security retweeted
16 Mar 2020
Big news! We’re excited to announce that @npmjs will be joining @GitHub! We're thrilled to join an organization as committed to open source as we are, so that the npm registry can remain free & public forever. You can read more about this new chapter here: buff.ly/3aYygVf
49
1,345
2,971
Node.js Security retweeted
Going live at 9AM PT! Will be talking about JavaScript ecosystem security and solutions you can get involved in.
We’re live at noon EST / 9am PST with our very special guest @ronperris 😎! Feel free to ask questions on the YT live chat, in Slack (link on absoluteappsec.com) or email us at absoluteappsec@gmail.com. youtube.com/watch?v=2bs6gQjL…
3
9
Did you ever want to know how a pentester makes their way from bug to exploit? Read about how @truesec found and exploited a bug in hot-formula-parser (CVE-2020-6836) blog.truesec.com/2020/01/17/…

1
2
9
Please update your npm cli to v6.13.4 as soon as you can. npm i npm -g blog.npmjs.org/post/18961860…

8
102
123
Node.js Security retweeted
20 Nov 2019
the npm security team has been hard at work building infrastructure to do behavioral analysis of npm packages at scale. vp of security, @adam_baldwin, explains what this entails ( a sneak peek at the security insights API): buff.ly/35ct9hw
6
10
This Node.js Best Practices guide by @nodepractices has some great security guidance. github.com/goldbergyoni/node…

13
38
Node.js Security retweeted
We get a lot of requests from people wanting to do research around malware in the Registry. It will be really exciting to see what the community does with this data!
16 Oct 2019
for years, npm has maintained the most complete corpus of malware published on the npm registry. learn more about the malware corpus by the numbers & what to look for in our security insights api: buff.ly/32nG67g
2
9
Did you miss us? Well we're back and tweeting. The npm security team has taken over the nodesecurity twitter account and will be keeping you up to date on JavaScript security related happenings.
9
38
The Node Security Platform Service is shutting down tomorrow: buff.ly/2KKjxAT

1
4
2
On 9/30 the Node Security Platform will stop working. Here’s what you can do: buff.ly/2KKjxAT

1
The Node Security Platform is shutting down on 9/30: buff.ly/2KKjxAT

2
3
JavaScript’s definitive listing of known package vulnerabilities is moving to @npmjs Here’s how to use it: buff.ly/2KKjxAT

7
5
HashWick - a new vulnerability found by @indutny - impacts all v8js releases.
4
9
Are you prepared to move on from the Node Security Platform service? Here’s what you can do: buff.ly/2KKjxAT

2
2