Skip to content

mattrq/ahead

Repository files navigation

AHead

Greenkeeper badge Build Status Known Vulnerabilities Build Status Quality Gate SonarCloud Coverage SonarCloud Bugs SonarCloud Vulnerabilities Code smells Technical debt

Command line tool to scan security header. Aims to be a CLI equivalent to securityheaders.io

Docs

Developent

Attribution:

The ideas and default rules set

Implementation for a rule bases node cil test tool have been borrowed from eslint

Todo / Ideas:

  • Make config extensible
  • CSP check for 'unsafe'
  • HSTS check for 'max < 1year'
  • HSTS check preload
  • HSTS check for subdomain
  • Server contains bad value
  • Examples of using tool with express and supertest
  • Add integration tests
  • Update output to match formatter
  • Push built package to NPM
  • Vary header not set

About

Command line tool to scan security headers. Aims to be a CLI equivalent to securityheaders.io

Topics

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Contributors 3

  •  
  •  
  •