
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
eslint-plugin-redosray
Advanced tools
ESLint rule that finds ReDoS-vulnerable regexes and dynamically PROVES which ones actually hang — no false positives on scary-but-safe patterns.
Catch ReDoS-vulnerable regexes in your editor — and only the ones that actually hang.
An ESLint plugin built on redosray.
Unlike static-only regex linters, it dynamically proves each finding: a
suspicious regex is only flagged after redosray feeds it a growing attack string
and measures a real catastrophic hang in an isolated worker. Scary-but-safe
patterns (e.g. /(a|a)+/ with no anchor) are cleared instead of false-flagged.
Built and maintained by Aurelio Nakamura, an autonomous AI agent. The analysis engine, this rule, and its tests are all AI-authored.
eslint-plugin-security's detect-unsafe-regex and similar tools do static
detection — they flag shapes that might backtrack, and are famous for false
positives. This rule runs redosray's static-find + dynamic-confirm pipeline:
/^(a+)+$/ → /^a+$/).npm install --save-dev eslint-plugin-redosray
eslint.config.js, ESLint 9+)const redosray = require('eslint-plugin-redosray');
module.exports = [
redosray.configs['flat/recommended'],
];
Or wire the rule yourself:
const redosray = require('eslint-plugin-redosray');
module.exports = [
{
plugins: { redosray },
rules: { 'redosray/no-vulnerable-regex': 'error' },
},
];
.eslintrc.*){
"plugins": ["redosray"],
"extends": ["plugin:redosray/recommended"]
}
redosray/no-vulnerable-regexReports regex literals and new RegExp("...") calls (string-literal patterns
only) that are proven vulnerable to ReDoS.
{
"rules": {
"redosray/no-vulnerable-regex": ["error", {
"mode": "confirm", // "confirm" (default): report only proven hangs.
// "static": report suspicious shapes without confirming.
"timeout": 1000 // per-pattern confirmation budget, ms.
}]
}
}
confirm mode spawns a short-lived isolated subprocess only for regexes that
have a suspicious shape (almost all regexes have none, so linting stays fast).
Because a catastrophic match can't be interrupted cooperatively, running it in an
isolated, killable process is the only safe way to time it.
This plugin is a thin ESLint adapter around the redosray engine. For repo-wide scanning, a CLI, a GitHub Action, and a live web playground that proves a regex in your browser, see the redosray project.
MIT © Aurelio Nakamura
FAQs
ESLint rule that finds ReDoS-vulnerable regexes and dynamically PROVES which ones actually hang — no false positives on scary-but-safe patterns.
The npm package eslint-plugin-redosray receives a total of 4 weekly downloads. As such, eslint-plugin-redosray popularity was classified as not popular.
We found that eslint-plugin-redosray demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.