
Product
Announcing Socket Fix 2.0
Socket Fix 2.0 brings targeted CVE remediation, smarter upgrade planning, and broader ecosystem support to help developers get to zero alerts.
no-object-forgery
Advanced tools
Monkeypatch JSON to distinguish parsed objects from those that originate in user code.
JSON.parse makes it easy to unintentionally turn untrustworthy strings into untrustworthy objects which has led to problems when key pieces of infrastructure are less suspicious of objects than of strings.
This monkeypatches JSON.parse
and provides an isParsedObject
function
that likely identifies objects that were parsed from strings that might
come from an untrusted source.
See Protecting against Object Forgery"
const isParsedObject = require('no-object-forgery');
// myJsonString might come from an attacker.
const x = JSON.parse(myJsonString);
if (isParsedObject(x)) {
// Don't treat x as privileged.
}
If you know that a string is trustworthy, you can parse an object that is not recognized as a parsed object.
JSON.parseTrusted(trustworthyJsonString);
This is not an official Google product.
FAQs
Monkeypatch JSON to distinguish parsed objects from those that originate in user code.
We found that no-object-forgery demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Product
Socket Fix 2.0 brings targeted CVE remediation, smarter upgrade planning, and broader ecosystem support to help developers get to zero alerts.
Security News
Socket CEO Feross Aboukhadijeh joins Risky Business Weekly to unpack recent npm phishing attacks, their limited impact, and the risks if attackers get smarter.
Product
Socket’s new Tier 1 Reachability filters out up to 80% of irrelevant CVEs, so security teams can focus on the vulnerabilities that matter.