Skip to content

Identify vulnerabilities in your API's using the OpenAPI Security Scanner

Notifications You must be signed in to change notification settings

cloudchefs/openapi-security-scanner

Repository files navigation

logo

Identify vulnerabilities in your API's using the OpenAPI Security Scanner


JavaScript Style Guide Build Status

Table of contents

Getting Started

$ npm install -g @openapi-security-scanner/cli
$ npx @openapi-security-scanner/cli

Usage

The scan command uses your OpenAPI definition, provided hostname and optional headers to start fuzzing your API.

npx @openapi-security-scanner/cli scan \
    --api-definition api.yaml \
    --host api.example.com \
    --headers "Cookie: ..."

Modules

Package Description
@openapi-security-scanner/cli Scan your API's in your CI/CD pipeline or from your local machine using the CLI
@openapi-security-scanner/fuzzers Collections of payloads that can be used for fuzzing
@openapi-security-scanner/request-generator Generate Postman collections and data sets for fuzzing your API
@openapi-security-scanner/util Utility functions for deduplicating shared logic

About

Identify vulnerabilities in your API's using the OpenAPI Security Scanner

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published