Skip to content

Secure your Next.js applications with @shipsecure/eslint-plugin-next, an ESLint plugin designed to detect and prevent common security vulnerabilities.

License

Notifications You must be signed in to change notification settings

ShipSecure-Labs/eslint-plugin-next

Repository files navigation

@shipsecure/eslint-plugin-next

Overview

@shipsecure/eslint-plugin-next is a custom ESLint plugin designed to enhance the security of Next.js applications by identifying potentially insecure patterns in code. This plugin offers a set of rules specifically tailored to prevent common security pitfalls in Next.js, encouraging best practices and securing your app's frontend and backend code.

Features

  • Rules for Secure Code: Detects usage of unsecure URLs, inline scripts, eval, and other potential security vulnerabilities.
  • Recommended Configurations: Provides a recommended set of rules for immediate security improvements.
  • Easy to Integrate: Seamlessly integrates with any Next.js project with simple installation and configuration.

Installation

npm install @shipsecure/eslint-plugin-next --save-dev

Usage

Flat config (requires eslint >= v8.23.0)

Add the following to your eslint.config.js file:

const shipsecureNext = require("@shipsecure/eslint-plugin-next");

module.exports = [shipsecureNext.configs.recommended];

eslintrc config (deprecated)

Add the following to your .eslintrc file:

module.exports = {
  extends: ["plugin:@shipsecure/next/recommended-legacy"],
};

Contributing

Contributions are welcome! If you'd like to add new rules, suggest enhancements, or report issues, please open a pull request or issue on our GitHub repository.

Steps to Contribute

  1. Fork the repository.
  2. Create a new branch for your feature (git checkout -b feature-name).
  3. Make your changes and add tests.
  4. Run tests to ensure everything works (npm test).
  5. Push your branch and submit a pull request.

License

This project is licensed under the MIT License - see the LICENSE file for details.

About

Secure your Next.js applications with @shipsecure/eslint-plugin-next, an ESLint plugin designed to detect and prevent common security vulnerabilities.

Topics

Resources

License

Stars

Watchers

Forks