{"_id":"@bramkortooms/sectester-runner","_rev":"5-57087473fcc095fa03c0df643a2a3f64","name":"@bramkortooms/sectester-runner","dist-tags":{"latest":"0.43.2-test4"},"versions":{"0.43.2-test.20250622131555":{"name":"@bramkortooms/sectester-runner","version":"0.43.2-test.20250622131555","keywords":["security","testing","e2e","test","typescript","appsec","pentesting","qa","brightsec"],"author":{"name":"Artem Derevnjuk","email":"artem.derevnjuk@brightsec.com"},"license":"MIT","_id":"@bramkortooms/sectester-runner@0.43.2-test.20250622131555","maintainers":[{"name":"bramkortooms","email":"bramkortooms@gmail.com"}],"homepage":"https://github.com/NeuraLegion/sectester-js#readme","bugs":{"url":"https://github.com/NeuraLegion/sectester-js/issues"},"dist":{"shasum":"e178fed7c7b3e7a82e7a6088d389eb9c5a784fcc","tarball":"https://registry.npmjs.org/@bramkortooms/sectester-runner/-/sectester-runner-0.43.2-test.20250622131555.tgz","fileCount":24,"integrity":"sha512-Aa9rfP8ueln+KL52qBMPqOZkLV0r2L1ytlwr3GmXvgSB6Dug4vIcOEwhAP9urhdUc0FH2aAVWXtG4AmEfCuZKQ==","signatures":[{"sig":"MEQCIENUtjp6iSaNAyYeBgseZ3s+htIJAdLZgtYaMZW8BDiVAiBwq0akziFL+RDUu5xJZBMqOd4c315SsdUQbqjqTwmOtA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":29280},"engines":{"npm":">=10","node":">=18"},"gitHead":"dbd44aba1c298c57e7bc03d4a554235f222c06d3","_npmUser":{"name":"bramkortooms","actor":{"name":"bramkortooms","type":"user","email":"bramkortooms@gmail.com"},"email":"bramkortooms@gmail.com"},"repository":{"url":"git+https://github.com/NeuraLegion/sectester-js.git","type":"git"},"_npmVersion":"10.9.0","description":"Run scanning for vulnerabilities just from your unit tests on CI phase.","directories":{},"_nodeVersion":"22.12.0","dependencies":{"tslib":"~2.6.3","fastify":"^4.28.1"},"_hasShrinkwrap":false,"peerDependencies":{"@sectester/core":">=0.16.0 <1.0.0","@sectester/repeater":">=0.16.0 <1.0.0","@sectester/reporter":">=0.16.0 <1.0.0","@bramkortooms/sectester-scan":">=0.16.0 <1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/sectester-runner_0.43.2-test.20250622131555_1750587360807_0.6788462381009002","host":"s3://npm-registry-packages-npm-production"}},"0.43.2-test.20250622134229":{"name":"@bramkortooms/sectester-runner","version":"0.43.2-test.20250622134229","keywords":["security","testing","e2e","test","typescript","appsec","pentesting","qa","brightsec"],"author":{"name":"Artem Derevnjuk","email":"artem.derevnjuk@brightsec.com"},"license":"MIT","_id":"@bramkortooms/sectester-runner@0.43.2-test.20250622134229","maintainers":[{"name":"bramkortooms","email":"bramkortooms@gmail.com"}],"homepage":"https://github.com/NeuraLegion/sectester-js#readme","bugs":{"url":"https://github.com/NeuraLegion/sectester-js/issues"},"dist":{"shasum":"c3ead98c5403643523602bd09452a50f46dbd79a","tarball":"https://registry.npmjs.org/@bramkortooms/sectester-runner/-/sectester-runner-0.43.2-test.20250622134229.tgz","fileCount":24,"integrity":"sha512-bBqa6e+O4slOZRhDwuJemDudjNG2YSYxJwkmjcpNnAQUF/rbNTo7TXiAwat8IQZrm6NfM5xnjV5FM3b6YaTV6g==","signatures":[{"sig":"MEUCIG2NEUYarmSMu4MzyXkexdzS+p9TogwxZj4+CzpsJAiJAiEAw8D4+0O7TP7BwFa+LaxPDWI8OL95/mPtYMWXjRcITfk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":29291},"engines":{"npm":">=10","node":">=18"},"gitHead":"dbd44aba1c298c57e7bc03d4a554235f222c06d3","_npmUser":{"name":"bramkortooms","actor":{"name":"bramkortooms","type":"user","email":"bramkortooms@gmail.com"},"email":"bramkortooms@gmail.com"},"repository":{"url":"git+https://github.com/NeuraLegion/sectester-js.git","type":"git"},"_npmVersion":"10.9.0","description":"Run scanning for vulnerabilities just from your unit tests on CI phase.","directories":{},"_nodeVersion":"22.12.0","dependencies":{"tslib":"~2.6.3","fastify":"^4.28.1"},"_hasShrinkwrap":false,"peerDependencies":{"@sectester/core":">=0.16.0 <1.0.0","@sectester/repeater":">=0.16.0 <1.0.0","@sectester/reporter":">=0.16.0 <1.0.0","@bramkortooms/sectester-scan":"0.43.2-test.20250622134229"},"_npmOperationalInternal":{"tmp":"tmp/sectester-runner_0.43.2-test.20250622134229_1750588954091_0.16706515257347676","host":"s3://npm-registry-packages-npm-production"}},"0.43.2-test.20250622185029":{"name":"@bramkortooms/sectester-runner","version":"0.43.2-test.20250622185029","keywords":["security","testing","e2e","test","typescript","appsec","pentesting","qa","brightsec"],"author":{"name":"Artem Derevnjuk","email":"artem.derevnjuk@brightsec.com"},"license":"MIT","_id":"@bramkortooms/sectester-runner@0.43.2-test.20250622185029","maintainers":[{"name":"bramkortooms","email":"bramkortooms@gmail.com"}],"homepage":"https://github.com/NeuraLegion/sectester-js#readme","bugs":{"url":"https://github.com/NeuraLegion/sectester-js/issues"},"dist":{"shasum":"d099912bb5908176d9ba8921cf5fd5ca433e7398","tarball":"https://registry.npmjs.org/@bramkortooms/sectester-runner/-/sectester-runner-0.43.2-test.20250622185029.tgz","fileCount":24,"integrity":"sha512-iJi3AIkBMBqXYLPvIqDDp1YHG2IFXBUcrepfKD+T0Z4o2gAv2MXAphnZecCe87SNFv3mRPL/Jt9IR9SoIILyRg==","signatures":[{"sig":"MEUCIQDLOsXScyJvIRVOU55B9qcjn0qRCPKYXXGYhg7HjQgPEgIgW4VKuhOqreEabS4+9yH/F58dpicIwRfGuUyBe5PRw3Y=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":29474},"main":"./src/index.js","type":"commonjs","types":"./src/index.d.ts","engines":{"npm":">=10","node":">=18"},"gitHead":"dbd44aba1c298c57e7bc03d4a554235f222c06d3","_npmUser":{"name":"bramkortooms","actor":{"name":"bramkortooms","type":"user","email":"bramkortooms@gmail.com"},"email":"bramkortooms@gmail.com"},"repository":{"url":"git+https://github.com/NeuraLegion/sectester-js.git","type":"git"},"_npmVersion":"10.9.0","description":"Run scanning for vulnerabilities just from your unit tests on CI phase.","directories":{},"_nodeVersion":"22.12.0","dependencies":{"tslib":"~2.6.3","fastify":"^4.28.1"},"_hasShrinkwrap":false,"peerDependencies":{"@sectester/core":">=0.16.0 <1.0.0","@sectester/repeater":">=0.16.0 <1.0.0","@sectester/reporter":">=0.16.0 <1.0.0","@bramkortooms/sectester-scan":"0.43.2-test2"},"_npmOperationalInternal":{"tmp":"tmp/sectester-runner_0.43.2-test.20250622185029_1750607440296_0.3328072437651657","host":"s3://npm-registry-packages-npm-production"}},"0.43.2-test3":{"name":"@bramkortooms/sectester-runner","version":"0.43.2-test3","keywords":["security","testing","e2e","test","typescript","appsec","pentesting","qa","brightsec"],"author":{"name":"Artem Derevnjuk","email":"artem.derevnjuk@brightsec.com"},"license":"MIT","_id":"@bramkortooms/sectester-runner@0.43.2-test3","maintainers":[{"name":"bramkortooms","email":"bramkortooms@gmail.com"}],"homepage":"https://github.com/NeuraLegion/sectester-js#readme","bugs":{"url":"https://github.com/NeuraLegion/sectester-js/issues"},"dist":{"shasum":"79e6aae68128f4a94602692f8e5ac241fe84d3f6","tarball":"https://registry.npmjs.org/@bramkortooms/sectester-runner/-/sectester-runner-0.43.2-test3.tgz","fileCount":24,"integrity":"sha512-yGvu0oR2To1281o3jEJtjNlAS1X7DCSt8rrDFYkb2hS2xuAaDempIuop2QF40zL3/4B3tQt7/n8civOvngPNag==","signatures":[{"sig":"MEQCIE7RQAzuq3F8dtRig3Y3mhtwIml7Tt7gnYuQsqMC+OXiAiBCh2THQuskMG2cgW18hv9MClxFCzTfMXn9wrSp19n9CQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":29460},"main":"./src/index.js","type":"commonjs","types":"./src/index.d.ts","engines":{"npm":">=10","node":">=18"},"gitHead":"dbd44aba1c298c57e7bc03d4a554235f222c06d3","_npmUser":{"name":"bramkortooms","actor":{"name":"bramkortooms","type":"user","email":"bramkortooms@gmail.com"},"email":"bramkortooms@gmail.com"},"repository":{"url":"git+https://github.com/NeuraLegion/sectester-js.git","type":"git"},"_npmVersion":"10.9.0","description":"Run scanning for vulnerabilities just from your unit tests on CI phase.","directories":{},"_nodeVersion":"22.12.0","dependencies":{"tslib":"~2.6.3","fastify":"^4.28.1"},"_hasShrinkwrap":false,"peerDependencies":{"@sectester/core":">=0.16.0 <1.0.0","@sectester/repeater":">=0.16.0 <1.0.0","@sectester/reporter":">=0.16.0 <1.0.0","@bramkortooms/sectester-scan":"0.43.2-test2"},"_npmOperationalInternal":{"tmp":"tmp/sectester-runner_0.43.2-test3_1750607699744_0.10616895982297803","host":"s3://npm-registry-packages-npm-production"}},"0.43.2-test4":{"name":"@bramkortooms/sectester-runner","version":"0.43.2-test4","description":"Run scanning for vulnerabilities just from your unit tests on CI phase.","repository":{"type":"git","url":"git+https://github.com/NeuraLegion/sectester-js.git"},"engines":{"node":">=18","npm":">=10"},"author":{"name":"Artem Derevnjuk","email":"artem.derevnjuk@brightsec.com"},"license":"MIT","bugs":{"url":"https://github.com/NeuraLegion/sectester-js/issues"},"keywords":["security","testing","e2e","test","typescript","appsec","pentesting","qa","brightsec"],"dependencies":{"fastify":"^4.28.1","tslib":"~2.6.3"},"peerDependencies":{"@sectester/core":">=0.16.0 <1.0.0","@sectester/repeater":">=0.16.0 <1.0.0","@sectester/reporter":">=0.16.0 <1.0.0","@bramkortooms/sectester-scan":"0.43.2-test4"},"types":"./src/index.d.ts","main":"./src/index.js","type":"commonjs","_id":"@bramkortooms/sectester-runner@0.43.2-test4","gitHead":"dbd44aba1c298c57e7bc03d4a554235f222c06d3","homepage":"https://github.com/NeuraLegion/sectester-js#readme","_nodeVersion":"22.12.0","_npmVersion":"10.9.0","dist":{"integrity":"sha512-WGapwfiIcFc/8rLkNp1d3PjlrkYEzSH6hWIdm2FLFGd5EHoHHd7lCFpEumqDOIXusmg0BhNcSWsm33JT3daXog==","shasum":"e8a3907ae383e02724b8e332a04adbddd0f0dcf4","tarball":"https://registry.npmjs.org/@bramkortooms/sectester-runner/-/sectester-runner-0.43.2-test4.tgz","fileCount":24,"unpackedSize":29460,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCRGRaIQG+QPCYssBx2GSUb2tr8sndOQHqKlu4a8UT9dgIhAOJhJSkjbhHTEse4rShlU5XR1UNd/1AmlTPX9ZGVDOOB"}]},"_npmUser":{"name":"bramkortooms","email":"bramkortooms@gmail.com","actor":{"name":"bramkortooms","email":"bramkortooms@gmail.com","type":"user"}},"directories":{},"maintainers":[{"name":"bramkortooms","email":"bramkortooms@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/sectester-runner_0.43.2-test4_1750607889984_0.13707749637255517"},"_hasShrinkwrap":false}},"time":{"created":"2025-06-22T10:16:00.715Z","modified":"2025-06-22T15:58:10.318Z","0.43.2-test.20250622131555":"2025-06-22T10:16:00.976Z","0.43.2-test.20250622134229":"2025-06-22T10:42:34.323Z","0.43.2-test.20250622185029":"2025-06-22T15:50:40.535Z","0.43.2-test3":"2025-06-22T15:54:59.926Z","0.43.2-test4":"2025-06-22T15:58:10.148Z"},"bugs":{"url":"https://github.com/NeuraLegion/sectester-js/issues"},"author":{"name":"Artem Derevnjuk","email":"artem.derevnjuk@brightsec.com"},"license":"MIT","homepage":"https://github.com/NeuraLegion/sectester-js#readme","keywords":["security","testing","e2e","test","typescript","appsec","pentesting","qa","brightsec"],"repository":{"type":"git","url":"git+https://github.com/NeuraLegion/sectester-js.git"},"description":"Run scanning for vulnerabilities just from your unit tests on CI phase.","maintainers":[{"name":"bramkortooms","email":"bramkortooms@gmail.com"}],"readme":"# @sectester/runner\n\n[![Maintainability](https://api.codeclimate.com/v1/badges/a5f72ececc9b0f402802/maintainability)](https://codeclimate.com/github/NeuraLegion/sectester-js/maintainability)\n[![Test Coverage](https://api.codeclimate.com/v1/badges/a5f72ececc9b0f402802/test_coverage)](https://codeclimate.com/github/NeuraLegion/sectester-js/test_coverage)\n![Build Status](https://github.com/NeuraLegion/sectester-js/actions/workflows/coverage.yml/badge.svg?branch=master&event=push)\n![NPM Downloads](https://img.shields.io/npm/dw/@sectester/core)\n\nRun scanning for vulnerabilities just from your unit tests on CI phase.\n\n## Setup\n\n```bash\nnpm i -s @sectester/runner\n```\n\n## Step-by-step guide\n\n### Configure SDK\n\nTo start writing tests, first obtain a Bright token, which is required for the access to Bright API. More info about [setting up an API key](https://docs.brightsec.com/docs/manage-your-personal-account#manage-your-personal-api-keys-authentication-tokens).\n\nThen put obtained token into `BRIGHT_TOKEN` environment variable to make it accessible by default [`EnvCredentialProvider`](https://github.com/NeuraLegion/sectester-js/tree/master/packages/core#envcredentialprovider).\n\n> Refer to `@sectester/core` package [documentation](https://github.com/NeuraLegion/sectester-js/tree/master/packages/core#credentials) for the details on alternative ways of configuring credential providers.\n\nOnce it is done, create a configuration object. Single required option is Bright `hostname` domain you are going to use, e.g. `app.brightsec.com` as the main one:\n\n```ts\nimport { Configuration } from '@sectester/core';\n\nconst configuration = new Configuration({ hostname: 'app.brightsec.com' });\n```\n\n### Setup runner\n\nTo set up a runner, create `SecRunner` instance passing a previously created configuration as follows:\n\n```ts\nimport { Configuration } from '@sectester/core';\nimport { SecRunner } from '@sectester/runner';\n\nconst configuration = new Configuration({\n  hostname: 'app.brightsec.com',\n  projectId: 'your project ID'\n});\nconst runner = new SecRunner(configuration);\n\n// or\n\nconst runner2 = new SecRunner({\n  hostname: 'app.brightsec.com',\n  projectId: 'your project ID'\n});\n```\n\nAfter that, you have to initialize a `SecRunner` instance:\n\n```ts\nawait runner.init();\n```\n\nThe runner is now ready to perform your tests, but you have to create a scan.\n\nTo dispose a runner, you just need to call the `clear` method:\n\n```ts\nawait runner.clear();\n```\n\n### Starting scan\n\nTo start scanning your application, first you have to create a `SecScan` instance, as shown below:\n\n```ts\nconst scan = runner.createScan({ tests: ['xss'] });\n```\n\nBelow you will find a list of parameters that can be used to configure a `Scan`:\n\n| Option                 | Description                                                                                                                                                                                                                                                |\n| ---------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |\n| `tests`                | The list of tests to be performed against the target application. To retrieve the complete list, send a request to the [API](https://app.brightsec.com/api/v1/scans/tests). [Learn more about tests](https://docs.brightsec.com/docs/vulnerability-guide). |\n| `smart`                | Minimize scan time by using automatic smart decisions regarding parameter skipping, detection phases, etc. Enabled by default.                                                                                                                             |\n| `skipStaticParams`     | Use an advanced algorithm to automatically determine if a parameter has any effect on the target system's behavior when changed, and skip testing such static parameters. Enabled by default.                                                              |\n| `poolSize`             | Sets the maximum concurrent requests for the scan, to control the load on your server. By default, `10`.                                                                                                                                                   |\n| `attackParamLocations` | Defines which part of the request to attack. By default, `body`, `query`, and `fragment`.                                                                                                                                                                  |\n| `name`                 | The scan name. The method and hostname by default, e.g. `GET example.com`.                                                                                                                                                                                 |\n\n#### Endpoint scan\n\nTo scan an existing endpoint in your application, invoke the run method with a `TargetOptions` argument.\nFor `TargetOptions` details, please refer to this [link](https://github.com/NeuraLegion/sectester-js/tree/master/packages/scan#defining-a-target-for-attack).\n\nExample:\n\n```ts\nawait scan.run({\n  method: 'POST',\n  url: 'https://localhost:8000/api/orders',\n  body: { subject: 'Test', body: \"<script>alert('xss')</script>\" }\n});\n```\n\n#### Function scan\n\nTo focus on the security aspects of a particular function in your application, you can perform a function-specific scan.\nThis automatically creates an auxiliary target with a POST endpoint under the hood.\n\nExample:\n\n```ts\nconst inputSample = {\n  from: '2022-11-30',\n  to: '2024-06-21'\n};\n// assuming `calculateWeekdays` is your function under test\nconst fn = ({ from, to }) => calculateWeekdays(from, to);\n\nconst scan = runner.createScan({ tests: ['date_manipulation'] });\nawait scan.run({ inputSample, fn });\n```\n\n#### Scan execution details\n\nThe `run` method returns promise that is resolved if scan finishes without any vulnerability found, and is rejected otherwise (on founding issue that meets threshold, on timeout, on scanning error).\n\nIf any vulnerabilities are found, they will be pretty printed to stdout or stderr (depending on severity) by [reporter](https://github.com/NeuraLegion/sectester-js/tree/master/packages/reporter).\n\nBy default, each found issue will cause the scan to stop. To control this behavior you can set a severity threshold using the `threshold` method:\n\n```ts\nscan.threshold(Severity.HIGH);\n```\n\nNow found issues with severity lower than `HIGH` will not cause the scan to stop.\n\nSometimes either due to scan configuration issues or target misbehave, the scan might take much more time than you expect.\nIn this case, you can provide a timeout (in milliseconds) for specifying maximum scan running time:\n\n```ts\nscan.timeout(30000);\n```\n\nIn that case after 30 seconds, if the scan isn't finishing or finding any vulnerability, it will throw an error.\nThe default timeout value for `SecScan` is 10 minutes.\n\n### Usage sample\n\n```ts\nimport { SecRunner, SecScan } from '@sectester/runner';\n\ndescribe('/api', () => {\n  let runner!: SecRunner;\n  let scan!: SecScan;\n\n  beforeEach(async () => {\n    runner = new SecRunner({\n      hostname: 'app.brightsec.com',\n      projectId: 'your project ID'\n    });\n\n    await runner.init();\n\n    scan = runner\n      .createScan({ tests: ['xss'] })\n      .threshold(Severity.MEDIUM) // i. e. ignore LOW severity issues\n      .timeout(300000); // i. e. fail if last longer than 5 minutes\n  });\n\n  afterEach(async () => {\n    await runner.clear();\n  });\n\n  describe('/orders', () => {\n    it('should not have persistent xss', async () => {\n      await scan.run({\n        method: 'POST',\n        url: 'https://localhost:8000/api/orders',\n        body: { subject: 'Test', body: \"<script>alert('xss')</script>\" }\n      });\n    });\n\n    it('should not have reflective xss', async () => {\n      await scan.run({\n        url: 'https://localhost:8000/api/orders',\n        query: {\n          q: `<script>alert('xss')</script>`\n        }\n      });\n    });\n  });\n});\n```\n\n## License\n\nCopyright © 2025 [Bright Security](https://brightsec.com/).\n\nThis project is licensed under the MIT License - see the [LICENSE file](LICENSE) for details.\n","readmeFilename":"README.md"}