Forem

# opensourcesecurity

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
GitHub “besieged” by malware repositories and repo confusion: Why you'll be ok
Cover image for GitHub “besieged” by malware repositories and repo confusion: Why you'll be ok

GitHub “besieged” by malware repositories and repo confusion: Why you'll be ok

4
Comments 1
8 min read
Preventing server-side request forgery in Node.js applications
Cover image for Preventing server-side request forgery in Node.js applications

Preventing server-side request forgery in Node.js applications

6
Comments
8 min read
10 GitHub Security Best Practices
Cover image for 10 GitHub Security Best Practices

10 GitHub Security Best Practices

3
Comments
14 min read
7 tips to become a successful bug bounty hunter
Cover image for 7 tips to become a successful bug bounty hunter

7 tips to become a successful bug bounty hunter

18
Comments 1
5 min read
Understanding and mitigating the Jinja2 XSS vulnerability (CVE-2024-22195)
Cover image for Understanding and mitigating the Jinja2 XSS vulnerability (CVE-2024-22195)

Understanding and mitigating the Jinja2 XSS vulnerability (CVE-2024-22195)

6
Comments
5 min read
Handling security vulnerabilities in Spring Boot
Cover image for Handling security vulnerabilities in Spring Boot

Handling security vulnerabilities in Spring Boot

4
Comments 2
6 min read
Dependency injection in Python
Cover image for Dependency injection in Python

Dependency injection in Python

5
Comments
12 min read
The art of conditional rendering: Tips and tricks for React and Next.js developers
Cover image for The art of conditional rendering: Tips and tricks for React and Next.js developers

The art of conditional rendering: Tips and tricks for React and Next.js developers

8
Comments 2
11 min read
How to update cURL
Cover image for How to update cURL

How to update cURL

8
Comments
8 min read
Critical WebP 0-day security CVE-2023-4863 impacts wider software ecosystem
Cover image for Critical WebP 0-day security CVE-2023-4863 impacts wider software ecosystem

Critical WebP 0-day security CVE-2023-4863 impacts wider software ecosystem

1
Comments
9 min read
How to implement SSL/TLS pinning in Node.js
Cover image for How to implement SSL/TLS pinning in Node.js

How to implement SSL/TLS pinning in Node.js

4
Comments
9 min read
Streamline dependency updates with Mergify and Snyk
Cover image for Streamline dependency updates with Mergify and Snyk

Streamline dependency updates with Mergify and Snyk

1
Comments
7 min read
.NET developers alert: Moq NuGET package exfiltrates user emails from git
Cover image for .NET developers alert: Moq NuGET package exfiltrates user emails from git

.NET developers alert: Moq NuGET package exfiltrates user emails from git

6
Comments
4 min read
The importance of verifying webhook signatures
Cover image for The importance of verifying webhook signatures

The importance of verifying webhook signatures

Comments
8 min read
Finding and fixing insecure direct object references in Python
Cover image for Finding and fixing insecure direct object references in Python

Finding and fixing insecure direct object references in Python

1
Comments
6 min read
Session management security: Best practices for protecting user sessions
Cover image for Session management security: Best practices for protecting user sessions

Session management security: Best practices for protecting user sessions

4
Comments
11 min read
Using insecure npm package manager defaults to steal your macOS keyboard shortcuts
Cover image for Using insecure npm package manager defaults to steal your macOS keyboard shortcuts

Using insecure npm package manager defaults to steal your macOS keyboard shortcuts

Comments
5 min read
SnakeYaml 2.0: Solving the unsafe deserialization vulnerability
Cover image for SnakeYaml 2.0: Solving the unsafe deserialization vulnerability

SnakeYaml 2.0: Solving the unsafe deserialization vulnerability

3
Comments
5 min read
Top 8 penetration testing tools
Cover image for Top 8 penetration testing tools

Top 8 penetration testing tools

7
Comments 2
5 min read
How to generate an SBOM for JavaScript and Node.js applications
Cover image for How to generate an SBOM for JavaScript and Node.js applications

How to generate an SBOM for JavaScript and Node.js applications

4
Comments
11 min read
The npm faker package and the unexpected demise of open source libraries

The npm faker package and the unexpected demise of open source libraries

9
Comments
10 min read
loading...