{"_id":"rnsec","_rev":"5-e4b1280b246676d9a3efc0c2c8c32bc3","name":"rnsec","dist-tags":{"latest":"1.3.0"},"versions":{"1.0.0":{"name":"rnsec","version":"1.0.0","keywords":["react-native","security","scanner","static-analysis","vulnerability","expo","mobile","android","ios","security-audit","sast","code-analysis","security-scanner","mobile-security","security-testing","code-security","appsec"],"author":{"name":"adnxy","email":"adnanpoviolabs@gmail.com"},"license":"MIT","_id":"rnsec@1.0.0","maintainers":[{"name":"adnans","email":"adnan4sahinovic@gmail.com"}],"homepage":"https://github.com/adnxy/rnsec#readme","bugs":{"url":"https://github.com/adnxy/rnsec/issues"},"bin":{"rnsec":"dist/index.js"},"dist":{"shasum":"070039527170a923cc5179f05e5232751a0cc8a9","tarball":"https://registry.npmjs.org/rnsec/-/rnsec-1.0.0.tgz","fileCount":31,"integrity":"sha512-iHE/Zp3URSThOD96JAdDdqAD7zfF9YY/nv69j00t/snpPkAM+KCFJmp9cySWr0VsUuQUk+KstmMywCR372rspA==","signatures":[{"sig":"MEUCIQDlSNVDmzuXJ+sbFUvDa1NVgEhGqOgKPVZCcR3avf7hdAIgeWHzUFVvpZOjZE8Dnf78NDbqUP/lx3/imV4keb+18Fk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":272036},"main":"dist/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"9e999a62d6c59349a38ffb02968864afd7c2b29b","scripts":{"dev":"ts-node src/index.ts","lint":"tsc --noEmit","test":"echo \"Tests coming soon\" && exit 0","build":"tsc","clean":"rm -rf dist","prepublishOnly":"npm run build"},"_npmUser":{"name":"adnans","email":"adnan4sahinovic@gmail.com"},"repository":{"url":"git+https://github.com/adnxy/rnsec.git","type":"git"},"_npmVersion":"9.9.4","description":"Zero-config security scanner for React Native & Expo apps. Find vulnerabilities with 63 security rules covering Android, iOS, and React Native specific issues.","directories":{},"_nodeVersion":"20.19.6","dependencies":{"ora":"^9.0.0","boxen":"^8.0.1","chalk":"^5.6.2","commander":"^14.0.2","fast-glob":"^3.3.3","@babel/types":"^7.26.3","@babel/parser":"^7.26.3","@babel/traverse":"^7.26.5","gradient-string":"^3.0.0"},"_hasShrinkwrap":false,"devDependencies":{"ts-node":"^10.9.2","typescript":"^5.9.3","@types/glob":"^8.1.0","@types/node":"^24.10.1","@types/commander":"^2.12.0","@types/babel__traverse":"^7.20.6"},"_npmOperationalInternal":{"tmp":"tmp/rnsec_1.0.0_1766618892954_0.7155595128493881","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"rnsec","version":"1.0.1","keywords":["react-native","security","scanner","static-analysis","vulnerability","expo","mobile","android","ios","security-audit","sast","code-analysis","security-scanner","mobile-security","security-testing","code-security","appsec"],"author":{"name":"adnxy","email":"adnanpoviolabs@gmail.com"},"license":"MIT","_id":"rnsec@1.0.1","maintainers":[{"name":"adnans","email":"adnan4sahinovic@gmail.com"}],"homepage":"https://github.com/adnxy/rnsec#readme","bugs":{"url":"https://github.com/adnxy/rnsec/issues"},"bin":{"rnsec":"dist/index.js"},"dist":{"shasum":"7fe5ed4cc61d59324362549d6dbfd5ad72463e00","tarball":"https://registry.npmjs.org/rnsec/-/rnsec-1.0.1.tgz","fileCount":31,"integrity":"sha512-YJ+1+wMYB0oEdHKU//y8XF+n3XU+uTyvGkjhY4YxVmwUd+P0haNhXMdVNrrYjMCQUkM/SUJboCVmiFshlmVd6w==","signatures":[{"sig":"MEUCIDcvykrspAiUpiTe5dMQmGLJk8mGWC1AAkol0gHp21eLAiEA5Vj8WIB61ch/GxOjV/HYL2Qrc2574J8DAB+cYfF5G5w=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":272059},"main":"dist/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"bf24214f97a5f03567f7f7e136b8811034b6d954","scripts":{"dev":"ts-node src/index.ts","lint":"tsc --noEmit","test":"echo \"Tests coming soon\" && exit 0","build":"tsc && cp src/core/template.html dist/core/template.html","clean":"rm -rf dist","prepublishOnly":"npm run build"},"_npmUser":{"name":"adnans","email":"adnan4sahinovic@gmail.com"},"repository":{"url":"git+https://github.com/adnxy/rnsec.git","type":"git"},"_npmVersion":"9.9.4","description":"Zero-config security scanner for React Native & Expo apps. Find vulnerabilities with 63 security rules covering Android, iOS, and React Native specific issues.","directories":{},"_nodeVersion":"20.19.6","dependencies":{"ora":"^9.0.0","boxen":"^8.0.1","chalk":"^5.6.2","commander":"^14.0.2","fast-glob":"^3.3.3","@babel/types":"^7.26.3","@babel/parser":"^7.26.3","@babel/traverse":"^7.26.5","gradient-string":"^3.0.0"},"_hasShrinkwrap":false,"devDependencies":{"ts-node":"^10.9.2","typescript":"^5.9.3","@types/glob":"^8.1.0","@types/node":"^24.10.1","@types/commander":"^2.12.0","@types/babel__traverse":"^7.20.6"},"_npmOperationalInternal":{"tmp":"tmp/rnsec_1.0.1_1766619288205_0.3697468234789998","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"rnsec","version":"1.1.0","keywords":["react-native","security","scanner","static-analysis","vulnerability","expo","mobile","android","ios","security-audit","sast","code-analysis","security-scanner","mobile-security","security-testing","code-security","appsec"],"author":{"name":"adnxy","email":"adnanpoviolabs@gmail.com"},"license":"MIT","_id":"rnsec@1.1.0","maintainers":[{"name":"adnans","email":"adnan4sahinovic@gmail.com"}],"homepage":"https://github.com/adnxy/rnsec#readme","bugs":{"url":"https://github.com/adnxy/rnsec/issues"},"bin":{"rnsec":"dist/index.js"},"dist":{"shasum":"e698b8b682f312393c3f987da2365832f078ac4c","tarball":"https://registry.npmjs.org/rnsec/-/rnsec-1.1.0.tgz","fileCount":46,"integrity":"sha512-PYF3+MPZ34DNGqtVaVKqCIdBYzjBZcABwaOQLfCuhs4djjUbhC60E2HqAB3v91JD2ViCgX88fh16nxpt6D9+MA==","signatures":[{"sig":"MEUCIQDwz+N14wlSkWLYKyd/pCO6Tu8E55ofmYqF37mGGfY6hAIgZZsR22fQ5iJ2H6jX8x+UBYxGkweU5avnOEUloN80kRM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":475949},"main":"dist/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"defbc623188db60c8cf2099a1df57e4d97a63cbf","scripts":{"dev":"ts-node src/index.ts","lint":"tsc --noEmit","test":"echo \"Tests coming soon\" && exit 0","build":"tsc && cp src/core/template.html dist/core/template.html","clean":"rm -rf dist","prepublishOnly":"npm run build"},"_npmUser":{"name":"adnans","email":"adnan4sahinovic@gmail.com"},"repository":{"url":"git+https://github.com/adnxy/rnsec.git","type":"git"},"_npmVersion":"10.9.0","description":"Zero-config security scanner for React Native & Expo apps. Find vulnerabilities with 63 security rules covering Android, iOS, and React Native specific issues.","directories":{},"_nodeVersion":"22.11.0","dependencies":{"ora":"^9.0.0","boxen":"^8.0.1","chalk":"^5.6.2","commander":"^14.0.2","fast-glob":"^3.3.3","@babel/types":"^7.26.3","@babel/parser":"^7.26.3","@babel/traverse":"^7.26.5","gradient-string":"^3.0.0"},"_hasShrinkwrap":false,"devDependencies":{"ts-node":"^10.9.2","typescript":"^5.9.3","@types/glob":"^8.1.0","@types/node":"^24.10.1","@types/commander":"^2.12.0","@types/babel__traverse":"^7.20.6"},"_npmOperationalInternal":{"tmp":"tmp/rnsec_1.1.0_1768693234777_0.8425656937325381","host":"s3://npm-registry-packages-npm-production"}},"1.2.0":{"name":"rnsec","version":"1.2.0","keywords":["react-native","security","scanner","static-analysis","vulnerability","expo","mobile","android","ios","security-audit","sast","code-analysis","security-scanner","mobile-security","security-testing","code-security","appsec"],"author":{"name":"adnxy","email":"adnanpoviolabs@gmail.com"},"license":"MIT","_id":"rnsec@1.2.0","maintainers":[{"name":"adnans","email":"adnan4sahinovic@gmail.com"}],"homepage":"https://github.com/adnxy/rnsec#readme","bugs":{"url":"https://github.com/adnxy/rnsec/issues"},"bin":{"rnsec":"dist/index.js"},"dist":{"shasum":"6ea72b16ac1fc8bdac79f7c44dbe2747fdce76cd","tarball":"https://registry.npmjs.org/rnsec/-/rnsec-1.2.0.tgz","fileCount":49,"integrity":"sha512-BxcSKBN1F+ChxmOJs+sd5Fyu4wsdtMxybXQeZyQ5p5aF06Ee6cfB2GwpR0EyMh206Pk8t8jHf8orvVrvQrYBKg==","signatures":[{"sig":"MEUCIBoPvKgh57Eq+g6HQ9Dvd4RsABpgOAwGMqWNfbRxjsXOAiEAi4EdN6ndYd/KoV3CFWIxAtiZm9YgHXgRgiVwd3+PHNE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":500918},"main":"dist/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"37a30a3d6ea41699cc079d88115419fb3f9a2b34","scripts":{"dev":"ts-node src/index.ts","lint":"tsc --noEmit","test":"echo \"Tests coming soon\" && exit 0","build":"tsc && cp src/core/template.html dist/core/template.html","clean":"rm -rf dist","prepublishOnly":"npm run build"},"_npmUser":{"name":"adnans","email":"adnan4sahinovic@gmail.com"},"repository":{"url":"git+https://github.com/adnxy/rnsec.git","type":"git"},"_npmVersion":"10.9.0","description":"Zero-config security scanner for React Native & Expo apps. Find vulnerabilities with 68 security rules covering Android, iOS, and React Native specific issues.","directories":{},"_nodeVersion":"22.11.0","dependencies":{"ora":"^9.0.0","boxen":"^8.0.1","chalk":"^5.6.2","commander":"^14.0.2","fast-glob":"^3.3.3","@babel/types":"^7.26.3","@babel/parser":"^7.26.3","@babel/traverse":"^7.26.5","gradient-string":"^3.0.0"},"_hasShrinkwrap":false,"devDependencies":{"ts-node":"^10.9.2","typescript":"^5.9.3","@types/glob":"^8.1.0","@types/node":"^24.10.1","@types/commander":"^2.12.0","@types/babel__traverse":"^7.20.6"},"_npmOperationalInternal":{"tmp":"tmp/rnsec_1.2.0_1772716066128_0.03160867359784336","host":"s3://npm-registry-packages-npm-production"}},"1.3.0":{"name":"rnsec","version":"1.3.0","description":"Zero-config security scanner for React Native & Expo apps. Find vulnerabilities with 68 security rules covering Android, iOS, and React Native specific issues.","main":"dist/index.js","bin":{"rnsec":"dist/index.js"},"scripts":{"build":"tsc && cp src/core/template.html dist/core/template.html","dev":"ts-node src/index.ts","prepublishOnly":"npm run build","test":"npx tsx tests/rules.test.ts","lint":"tsc --noEmit","clean":"rm -rf dist"},"keywords":["react-native","security","scanner","static-analysis","vulnerability","expo","mobile","android","ios","security-audit","sast","code-analysis","security-scanner","mobile-security","security-testing","code-security","appsec"],"type":"module","author":{"name":"adnxy","email":"adnanpoviolabs@gmail.com"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/adnxy/rnsec.git"},"bugs":{"url":"https://github.com/adnxy/rnsec/issues"},"homepage":"https://github.com/adnxy/rnsec#readme","engines":{"node":">=18.0.0"},"dependencies":{"@babel/parser":"^7.26.3","@babel/traverse":"^7.26.5","@babel/types":"^7.26.3","boxen":"^8.0.1","chalk":"^5.6.2","commander":"^14.0.2","fast-glob":"^3.3.3","gradient-string":"^3.0.0","ora":"^9.0.0"},"devDependencies":{"@types/babel__traverse":"^7.20.6","@types/commander":"^2.12.0","@types/glob":"^8.1.0","@types/node":"^24.10.1","ts-node":"^10.9.2","typescript":"^5.9.3"},"_id":"rnsec@1.3.0","gitHead":"70355209e2aee8b28ad46e4ab1453fe7ecbc2e8d","_nodeVersion":"22.11.0","_npmVersion":"10.9.0","dist":{"integrity":"sha512-xdSp1SKTCiR7oEuc/Qanah8ipy5Q682eB/7IW9nqeX8nnOcwYInNruA1WoIl1ez928US2sARgnlFUzKKeOL9vA==","shasum":"3b8507cca50dc233303e0f19f1180574bb3c4bb5","tarball":"https://registry.npmjs.org/rnsec/-/rnsec-1.3.0.tgz","fileCount":35,"unpackedSize":377907,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQD/izIzNSAG6OKoqkhKfx8dz0bk4+3D3SiEMXTr7g6dlQIgR9urO6/QOJQH6MOfIRSWW/ZQRIBjPwCOQ76epoPX4vk="}]},"_npmUser":{"name":"adnans","email":"adnan4sahinovic@gmail.com"},"directories":{},"maintainers":[{"name":"adnans","email":"adnan4sahinovic@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/rnsec_1.3.0_1776633176560_0.5772662680854976"},"_hasShrinkwrap":false}},"time":{"created":"2025-12-24T23:28:12.953Z","modified":"2026-04-19T21:12:56.814Z","1.0.0":"2025-12-24T23:28:13.102Z","1.0.1":"2025-12-24T23:34:48.359Z","1.1.0":"2026-01-17T23:40:34.988Z","1.2.0":"2026-03-05T13:07:46.268Z","1.3.0":"2026-04-19T21:12:56.703Z"},"bugs":{"url":"https://github.com/adnxy/rnsec/issues"},"author":{"name":"adnxy","email":"adnanpoviolabs@gmail.com"},"license":"MIT","homepage":"https://github.com/adnxy/rnsec#readme","keywords":["react-native","security","scanner","static-analysis","vulnerability","expo","mobile","android","ios","security-audit","sast","code-analysis","security-scanner","mobile-security","security-testing","code-security","appsec"],"repository":{"type":"git","url":"git+https://github.com/adnxy/rnsec.git"},"description":"Zero-config security scanner for React Native & Expo apps. Find vulnerabilities with 68 security rules covering Android, iOS, and React Native specific issues.","maintainers":[{"name":"adnans","email":"adnan4sahinovic@gmail.com"}],"readme":"# rnsec\n\nA zero-configuration security scanner for React Native and Expo applications that detects vulnerabilities, hardcoded secrets, and security misconfigurations with a single command.\n\n[![npm version](https://img.shields.io/npm/v/rnsec.svg?style=flat)](https://www.npmjs.com/package/rnsec)\n[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](https://opensource.org/licenses/MIT)\n[![GitHub Issues](https://img.shields.io/github/issues/adnxy/rnsec.svg)](https://github.com/adnxy/rnsec/issues)\n[![GitHub Stars](https://img.shields.io/github/stars/adnxy/rnsec.svg)](https://github.com/adnxy/rnsec/stargazers)\n[![GitHub Sponsors](https://img.shields.io/github/sponsors/adnxy?style=flat&logo=github)](https://github.com/sponsors/adnxy)\n\n---\n\n## Installation\n\n### Global Installation (Recommended)\n\n```bash\nnpm install -g rnsec\n```\n\n### Using npx (No Installation Required)\n\n```bash\nnpx rnsec scan\n```\n\n### Building from Source\n\n```bash\ngit clone https://github.com/adnxy/rnsec.git\ncd rnsec\nnpm install\nnpm run build\nnpm link\n```\n\n## Quick Start\n\nScan your React Native or Expo project:\n\n```bash\nrnsec scan\n```\n\nView the generated HTML report:\n\n```bash\nopen rnsec-report.html\n```\n\nThat's it. No configuration needed.\n\n## Usage\n\n### Basic Commands\n\n**Scan current directory:**\n```bash\nrnsec scan\n```\n\n**HTML Report:**\n\n\n\n<img width=\"1058\" height=\"787\" alt=\"Screenshot 2025-12-25 at 00 56 44\" src=\"https://github.com/user-attachments/assets/6d265338-30a1-4008-a5d3-1061ee25bd1f\" />\n\n\n\n**Scan specific project:**\n```bash\nrnsec scan --path ./my-app\n```\n\n**Custom output filenames:**\n```bash\nrnsec scan --html security-report.html --output results.json\n```\n\n**CI/CD mode (silent, JSON only):**\n```bash\nrnsec scan --silent --output results.json\n```\n\n**Console JSON output (no files):**\n```bash\nrnsec scan --json\n```\n\n**View all security rules:**\n```bash\nrnsec rules\n```\n\n**Scan only changed files:**\n```bash\nrnsec scan --changed-files main\nrnsec scan --changed-files abc123\nrnsec scan --changed-files ${{ github.base_ref }}\n```\n\n### Command Options\n\n```bash\nrnsec scan [options]\n\nOptions:\n  -p, --path <path>      Project directory to scan (default: current directory)\n  --html <filename>      Custom HTML report filename\n  --output <filename>    Custom JSON report filename\n  --md <filename>        Generate Markdown report for PR comments\n  --json                 Output JSON to console only (no files)\n  --silent               Suppress console output\n  --changed-files <ref>  Scan only files changed since git reference (branch, commit, or tag)\n  -h, --help             Display help information\n  -V, --version          Display version number\n```\n\n### Exit Codes\n\n- `0` - No high-severity issues found\n- `1` - High-severity security issues detected\n\n## Changed Files Scanning\n\nThe `--changed-files` option allows you to scan only files that have changed since a specific git reference, making it perfect for CI/CD pipelines and pull request validation.\n\n### Usage\n\n```bash\n# Scan files changed since main branch\nrnsec scan --changed-files main\n\n# Scan files changed since specific commit\nrnsec scan --changed-files abc123def456\n\n# Scan files changed since a tag\nrnsec scan --changed-files v1.2.0\n\n# Use in CI/CD with JSON output\nrnsec scan --changed-files main --output security.json --silent\n```\n\n### Git References\n\nThe `--changed-files` option accepts any valid git reference:\n\n- **Branch names**: `main`, `develop`, `feature/new-auth`\n- **Commit hashes**: `abc123def456`, `HEAD~1`\n- **Tags**: `v1.0.0`, `release-2024`\n- **Special references**: `HEAD`, `origin/main`\n\n### CI/CD Integration\n\n**GitHub Actions:**\n```yaml\n- name: Run security scan on PR changes\n  run: rnsec scan --changed-files ${{ github.base_ref }} --output security.json --silent\n```\n\n**GitLab CI:**\n```yaml\nsecurity-scan:\n  script:\n    - rnsec scan --changed-files $CI_MERGE_REQUEST_TARGET_BRANCH_NAME --output security.json --silent\n```\n\n### Benefits\n\n- **Faster scans**: Only analyzes changed files instead of the entire codebase\n- **PR-focused**: Perfect for pull request validation\n- **CI/CD optimized**: Reduces pipeline execution time\n- **Incremental security**: Focus on new security issues introduced in changes\n\n## GitHub PR Comments Integration\n\nGenerate markdown reports that can be automatically posted as GitHub PR comments, bringing security results directly into your pull requests with advanced features like automatic comment updates, comparison tracking, and security metrics.\n\n### Usage\n\n```bash\n# Generate markdown report for PR comment\nrnsec scan --md security-report.md --silent\n\n# Combine with changed files for PR-focused scanning\nrnsec scan --changed-files main --md pr-security-report.md --silent\n```\n\n### Advanced Features\n\n#### Smart Comment Management\n- **Automatic updates**: Detects and updates existing comments instead of creating duplicates\n- **No spam**: Keeps PR conversations clean by updating the same comment\n- **Unique identifier**: Uses hidden HTML markers to identify rnsec comments\n\n#### Comparison Tracking\n- **New/resolved issues**: Automatically shows which issues were introduced or fixed\n- **Trend indicators**: Visual indicators for improving/declining security posture\n- **Historical data**: Stores scan results for comparison between runs\n\n#### Security Metrics\n- **Security score**: 0-100 score based on issue severity and count\n- **Vulnerability density**: Issues per 1000 lines of code\n- **Trend analysis**: Automatic detection of improving/declining/stable trends\n- **Visual dashboards**: Comprehensive metrics in markdown format\n\n#### Enhanced Formatting\n- **Collapsible sections**: Each severity level can be expanded/collapsed\n- **Code snippets**: Shows vulnerable code with syntax highlighting\n- **Better organization**: Reduces clutter for reports with many issues\n\n### GitHub Actions Workflow\n\nCopy the example workflow from `examples/github-actions/security-scan.yml`:\n\n```yaml\nname: 🔒 Security Scan\n\non:\n  pull_request:\n    branches: [ main, develop ]\n\njobs:\n  security-scan:\n    runs-on: ubuntu-latest\n    \n    steps:\n    - name: Checkout code\n      uses: actions/checkout@v4\n      with:\n        fetch-depth: 0\n    \n    - name: Install rnsec\n      run: npm install -g rnsec\n    \n    - name: Run security scan\n      run: |\n        rnsec scan --changed-files ${{ github.base_ref || 'main' }} --md security-report.md --output rnsec-report.json --silent\n      continue-on-error: true\n    \n    - name: Comment PR with security results\n      uses: actions/github-script@v7\n      with:\n        script: |\n          const fs = require('fs');\n          const markdownReport = fs.readFileSync('security-report.md', 'utf8');\n          const commentIdentifier = '<!-- rnsec-security-report -->';\n          \n          // Find and update existing comment\n          const { data: comments } = await github.rest.issues.listComments({\n            owner: context.repo.owner,\n            repo: context.repo.repo,\n            issue_number: context.issue.number,\n          });\n          \n          const existingComment = comments.find(c => c.body?.includes(commentIdentifier));\n          \n          if (existingComment) {\n            await github.rest.issues.updateComment({\n              owner: context.repo.owner,\n              repo: context.repo.repo,\n              comment_id: existingComment.id,\n              body: markdownReport\n            });\n          } else {\n            await github.rest.issues.createComment({\n              issue_number: context.issue.number,\n              owner: context.repo.owner,\n              repo: context.repo.repo,\n              body: markdownReport\n            });\n          }\n```\n\n### Multi-Platform Support\n\n#### GitLab CI/CD\nSee `examples/gitlab-ci/security-scan.yml` for GitLab merge request integration.\n\n#### Bitbucket Pipelines\nSee `examples/bitbucket-pipelines/bitbucket-pipelines.yml` for Bitbucket pull request integration.\n\n#### Azure DevOps\nSee `examples/azure-devops/azure-pipelines.yml` for Azure Pipelines integration.\n\n### Example PR Comment\n\nThe enhanced markdown report includes:\n- **Summary table** with issue counts by severity\n- **Comparison data** showing new/resolved issues since last scan\n- **Security metrics dashboard** with score and trends\n- **Collapsible findings** organized by severity\n- **Code snippets** with syntax highlighting\n- **Risk assessment** with clear action items\n- **Performance metrics** and scan information\n\n## Configuration\n\nrnsec supports configuration files to customize the scanning behavior. Create a `.rnsec.jsonc` or `.rnsec.json` file in your project root.\n\n### Ignoring Rules\n\nYou can ignore specific rules by adding them to the `ignoredRules` array:\n\n```jsonc\n{\n  \"ignoredRules\": [\n    \"ASYNCSTORAGE_SENSITIVE_KEY\",\n    \"LOGGING_SENSITIVE_DATA\"\n  ]\n}\n```\n\nTo find the rule ID for a specific finding, check the `ruleId` field in the JSON output or HTML report.\n\n### Excluding Files\n\nYou can exclude specific files and directories by adding exclude patterns to the `exclude` array:\n\n```jsonc\n{\n  \"exclude\": [\n    \"**/scripts/**\"\n  ]\n}\n```\n\nAny pattern supported by `fast-glob` can be used, for more information see [Pattern syntax](https://github.com/mrmlnc/fast-glob?tab=readme-ov-file#pattern-syntax).\n\n## What It Detects\n\nrnsec identifies 63 different security issues across 13 categories:\n\n**Common vulnerabilities found:**\n\n```typescript\n// Hardcoded API keys and secrets\nconst API_KEY = 'your_secret_api_key_here'; // Never commit real keys!\n\n// Insecure data storage\nawait AsyncStorage.setItem('user_token', token);\n\n// Unencrypted HTTP requests\nfetch('http://api.example.com/data');\n\n// Weak cryptographic algorithms\nconst hash = MD5(password);\n\n// Missing security properties\n<TextInput value={password} />  // Missing secureTextEntry\n```\n\n## Security Rules\n\nrnsec implements 63 security rules covering:\n\n| Category | Rules | Description |\n|----------|-------|-------------|\n| **Storage** | 7 | AsyncStorage security, encryption requirements, PII handling, Unencrypted MMKV |\n| **Network** | 13 | HTTP connections, SSL/TLS validation, WebView security |\n| **Authentication** | 6 | JWT handling, OAuth implementation, biometric authentication |\n| **Secrets** | 2 | API key detection (27+ patterns), hardcoded credentials |\n| **Cryptography** | 2 | Weak algorithms, hardcoded encryption keys |\n| **Logging** | 2 | Sensitive data exposure in logs |\n| **React Native** | 10 | Native bridge security, deep links, eval() usage |\n| **Debug** | 3 | Test credentials, development tools in production |\n| **Android** | 8 | Manifest security, Keystore issues, permission checks |\n| **iOS** | 8 | App Transport Security, Keychain usage, Info.plist |\n| **Config** | 1 | Dangerous permission configurations |\n| **WebView** | 1 | WebView injection vulnerabilities |\n| **Manifest** | 1 | Platform-specific manifest issues |\n\n### API Key Detection\n\nrnsec detects 27+ types of hardcoded API keys and secrets:\n\n- AWS Access Keys, Secret Keys, Session Tokens\n- Firebase API Keys\n- Google Cloud API Keys, OAuth tokens\n- Stripe Keys (Live, Test, Restricted)\n- GitHub Personal Access Tokens\n- GitLab Personal Access Tokens\n- Slack Tokens, Webhooks\n- Twilio API Keys, Auth Tokens\n- SendGrid API Keys\n- Mailgun API Keys\n- Mailchimp API Keys\n- Heroku API Keys\n- DigitalOcean Access Tokens\n- Private Keys (RSA, SSH, PGP, PKCS8)\n- JWT Tokens\n- Bearer Tokens\n- Generic API Keys and Secrets\n\n## Reports\n\nrnsec generates two report formats automatically:\n\n### HTML Report\n- Interactive dashboard with filtering capabilities\n- Syntax highlighting for code snippets\n- Categorized findings by severity\n- Quick navigation and search\n- Default filename: `rnsec-report.html`\n\n### JSON Report\n- Machine-readable format for automation\n- CI/CD pipeline integration\n- Programmatic analysis\n- Default filename: `rnsec-report.json`\n\n## CI/CD Integration\n\n### GitHub Actions\n\nCreate `.github/workflows/security.yml`:\n\n```yaml\nname: Security Scan\non:\n  push:\n    branches: [ main, develop ]\n  pull_request:\n    branches: [ main, develop ]\n\njobs:\n  security:\n    runs-on: ubuntu-latest\n    steps:\n      - name: Checkout code\n        uses: actions/checkout@v4\n      \n      - name: Setup Node.js\n        uses: actions/setup-node@v4\n        with:\n          node-version: '18'\n      \n      - name: Install rnsec\n        run: npm install -g rnsec\n      \n      - name: Run security scan\n        run: rnsec scan --output security.json --silent\n      \n      - name: Upload reports\n        uses: actions/upload-artifact@v4\n        if: always()\n        with:\n          name: security-report\n          path: |\n            security.json\n            rnsec-report.html\n```\n### EAS\n```yaml\nname: Security Scan\n\non:\n  push:\n    branches: [ main, develop ]\n  pull_request:\n    branches: [ main, develop ]\n\njobs:\n  security_scan:\n    type: build\n    params:\n      platform: android\n    steps:\n      - name: Security validation only\n        run: |\n          echo \"🔒 Running security validation...\"\n          echo \"Current directory: $(pwd)\"\n          echo \"Contents:\"\n          ls -la\n          \n          # Look for project in current and parent directories\n          echo \"🔍 Searching for project...\"\n          \n          # Check current directory first\n          if [ -f \"package.json\" ]; then\n            PROJECT_DIR=\".\"\n          else\n            # Check parent directory\n            if [ -f \"../package.json\" ]; then\n              PROJECT_DIR=\"..\"\n            else\n              # Search recursively\n              PROJECT_DIR=$(find .. -name \"package.json\" -type f -printf '%h' | head -1)\n            fi\n          fi\n          \n          if [ -z \"$PROJECT_DIR\" ] || [ ! -f \"$PROJECT_DIR/package.json\" ]; then\n            echo \"❌ No package.json found in any location\"\n            echo \"📁 Searching all directories:\"\n            find .. -name \"package.json\" -type f 2>/dev/null || echo \"No package.json found anywhere\"\n            exit 1\n          fi\n          \n          echo \"✅ Found project at: $PROJECT_DIR\"\n          cd \"$PROJECT_DIR\"\n          echo \"📁 Project contents:\"\n          ls -la | head -10\n          \n          # Install dependencies and run security scan\n          npm install -g rnsec\n          echo \"y\" | rnsec scan --output security.json\n          echo \"✅ Security validation completed\"\n```\n\n### GitLab CI\n\nAdd to `.gitlab-ci.yml`:\n\n```yaml\nsecurity-scan:\n  stage: test\n  image: node:18\n  script:\n    - npm install -g rnsec\n    - rnsec scan --output security.json --silent\n  artifacts:\n    paths:\n      - security.json\n      - rnsec-report.html\n    when: always\n```\n\n### Jenkins\n\n```groovy\nstage('Security Scan') {\n  steps {\n    sh 'npm install -g rnsec'\n    sh 'rnsec scan --output security.json --silent'\n    archiveArtifacts artifacts: 'security.json,rnsec-report.html', allowEmptyArchive: true\n  }\n}\n```\n\n## Examples\n\nTest rnsec with included sample projects:\n\n**Vulnerable application (35+ issues):**\n```bash\nrnsec scan --path examples/vulnerable-app\n```\n\n**Secure application (minimal issues):**\n```bash\nrnsec scan --path examples/secure-app\n```\n\n## Requirements\n\n- **Node.js**: Version 18 or higher\n- **Project Type**: React Native or Expo application\n\n## Why Use rnsec?\n\n### Simple\nOne command with zero configuration required. Works out of the box with any React Native or Expo project.\n\n### Comprehensive\n63 security rules covering all major vulnerability categories from OWASP Mobile Top 10 to platform-specific issues.\n\n### Fast\nScans complete projects in seconds using efficient static analysis techniques.\n\n### Mobile-First\nPurpose-built for React Native and Expo with Android and iOS platform-specific checks.\n\n### Actionable\nClear findings with code context, severity levels, and remediation guidance.\n\n### CI/CD Ready\nJSON output and exit codes designed for automated security pipelines.\n\n## Architecture\n\nrnsec uses static analysis to examine your codebase without executing it:\n\n1. **File Walker**: Recursively scans project files\n2. **AST Parser**: Analyzes JavaScript/TypeScript using Abstract Syntax Trees\n3. **Pattern Matching**: Detects secrets using regex patterns\n4. **Rule Engine**: Applies security rules to AST nodes\n5. **Platform Scanners**: Checks Android and iOS configuration files\n6. **Reporter**: Generates HTML and JSON reports\n\n## Contributing\n\nContributions are welcome! Please see [CONTRIBUTING.md](CONTRIBUTING.md) for details.\n\n### Ways to Contribute\n\n- **Report Bugs**: [Create a bug report](https://github.com/adnxy/rnsec/issues/new?template=bug_report.md)\n- **Request Features**: [Submit a feature request](https://github.com/adnxy/rnsec/issues/new?template=feature_request.md)\n- **Submit Pull Requests**: [Open a PR](https://github.com/adnxy/rnsec/pulls)\n- **Improve Documentation**: Help us make the docs better\n- **Add Security Rules**: Contribute new detection rules\n\n### Development Setup\n\nSee [DEVELOPMENT.md](DEVELOPMENT.md) for the complete developer guide.\n\n```bash\n# Clone repository\ngit clone https://github.com/adnxy/rnsec.git\ncd rnsec\n\n# Install dependencies\nnpm install\n\n# Build project\nnpm run build\n\n# Run tests\nnpm test\n\n# Link for local development\nnpm link\n```\n\n## Roadmap\n\nSee [ROADMAP.md](ROADMAP.md) for upcoming features and planned improvements.\n\n## Frequently Asked Questions\n\n**Q: Does rnsec modify my code?**  \nA: No. rnsec is a static analysis tool that only reads your code.\n\n**Q: Can I customize which rules run?**  \nA: Currently all rules run automatically. Custom rule configuration is planned for a future release.\n\n**Q: Does it work with TypeScript?**  \nA: Yes. rnsec fully supports both JavaScript and TypeScript.\n\n**Q: What about React Native Web?**  \nA: rnsec focuses on mobile security. Web-specific checks are not included.\n\n**Q: How do I exclude files or directories?**  \nA: rnsec automatically respects `.gitignore`. Additional exclusion options are planned.\n\n**Q: Does it replace manual security audits?**  \nA: No. rnsec is a complementary tool. Professional security audits are still recommended for production applications.\n\n## Limitations\n\nrnsec is a static analysis tool with inherent limitations:\n\n- **No Runtime Analysis**: Cannot detect issues that only appear during execution\n- **No Network Testing**: Does not test actual API endpoints or network security\n- **No Binary Analysis**: Does not analyze compiled native code\n- **Pattern-Based Detection**: May produce false positives or miss context-dependent issues\n- **Configuration Required**: Some security measures may be configured outside the codebase\n\n## Security Best Practices\n\nUsing rnsec is one part of a comprehensive security strategy:\n\n**Do:**\n- Review all findings manually to understand context\n- Use rnsec as part of your development workflow\n- Combine with other security tools and practices\n- Run scans regularly in CI/CD pipelines\n- Address high-severity issues promptly\n\n**Don't:**\n- Rely solely on static analysis for security\n- Ignore findings without investigation\n- Skip professional security audits for sensitive applications\n- Assume passing scans mean complete security\n\nFor production applications handling sensitive data, we strongly recommend professional security audits and penetration testing.\n\n## Support\n\n### Get Help\n\n- **Email**: adnanpoviolabs@gmail.com\n- **Issues**: [GitHub Issues](https://github.com/adnxy/rnsec/issues)\n- **Discussions**: [GitHub Discussions](https://github.com/adnxy/rnsec/discussions)\n\n### Support This Project\n\nIf rnsec helps secure your React Native apps, consider supporting its development:\n\n[![GitHub Sponsors](https://img.shields.io/badge/Sponsor-GitHub-ea4aaa?style=for-the-badge&logo=github)](https://github.com/sponsors/adnxy)\n\nYour sponsorship helps:\n- Maintain and improve rnsec\n- Add new security rules and features\n- Provide faster support and bug fixes\n- Keep the project free and open source\n\n### Report Security Vulnerabilities\n\nIf you discover a security vulnerability in rnsec itself, please email adnanpoviolabs@gmail.com directly instead of using public issue trackers.\n\n## License\n\nMIT License - see [LICENSE](LICENSE) file for details.\n\nCopyright (c) 2024 [adnxy](https://github.com/adnxy)\n\n## Acknowledgments\n\nBuilt for the React Native and Expo community. Special thanks to all contributors and users who help improve mobile security.\n\n---\n\n**Found this useful?** Consider giving it a star on GitHub to help others discover it.\n","readmeFilename":"README.md"}