nodeconf / US-CFP

Call for participation for NodeConf 2015
15 stars 0 forks source link

Dynamic Analysis Security Review Tool for JavaScript #28

Closed binarymist closed 9 years ago

binarymist commented 9 years ago

I'd like to see and hear a talk on someone building a tool to review all the untrusted JavaScript that many of our developers seem to be pulling into their projects without thought and well... just trusting it. A tool that will raise alarms when known vulnerabilities and possible buggy areas should be manually reviewed.

There's a new specification that addresses part of this issue: http://www.w3.org/TR/SRI/ Firefox and Chrome have initial implementations of this new specification.

mikeal commented 9 years ago

As you may have seen we had to cancel the speaking event at the Fox Theatre.

You're welcome to join us at Walker Creek Ranch for NodeConf Adventure which is an un-conference with attendee driven worksshops and discussion sessions. If you'd like to adapt this topic or any other idea to that format and you're planning on attending just log an issue in the Adventure repo.