nosurf
CSRF protection middleware for Go.
Awesome Golang Security resources πΆπ
This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.
CSRF protection middleware for Go.
Provides Cross-Site Request Forgery (CSRF) prevention middleware for Go web applications & services.
Encodes and decodes authenticated and optionally encrypted cookie values for Go web applications.
Secure is an HTTP middleware for Go that facilitates most of your security needs for web applications.
A drop-in replacement for http.Dir which disables directory indexing.
beego framework filter for easy security headers management.
Static analysis tool for Golang that protects against SQL injections. It does not seem to be actively maintained at the moment.
Inspects source code for security problems by scanning the Go AST and matching it with a set of rules. Comes bundled in a Docker container securego/gosec.
Concurrently runs most of the existing go linters and normalizes their output.
A tool that lets you query your code like data, in order to find vulnerabilities and bugs. See also LGTM.com for pull request integration and running queries in the cloud.
Find which of your Go lang direct GitHub dependencies is susceptible to ChainJacking attack.
The golang release mailing list. Language-specific security issues are announced here.
and JFrog VSCode Extension for Go - Free vulnerability data around Go Modules
Commercial but free listing of known vulnerabilities in libraries.
Vulnerabilities that were assigned a CVE. Covers the language and packages.
Golang known vulnerabilities in the National Vulnerability Database.
CFSSL is CloudFlare's PKI/TLS swiss army knife. It is both a command line tool and an HTTP API server for signing, verifying, and bundling TLS certificates.
Go Secure Example Application (GOSEA).
by OWASP - [PDF] Talk given by Sulhaedir at the OWASP Jakarta meetup.
by Checkmarx - Go programming language secure coding practices guide.
Handling data securely in memory.
[Video] GopherCon 2018, Liz Rice.
Simple Golang HTTPS/TLS Examples.
Hacking with Go for security professionals.
by Checkmarx - Diving Deep into Regular Expression Denial of Service (ReDoS) in Go.
A detailed description on Security assessment techniques for Go projects.
awesome-selfhosted/awesome-selfhosted
A list of Free Software network services and web applications which can be hosted on your own servers
lissy93/awesome-privacy
π¦ A curated list of privacy & security-focused software and services
vavkamil/awesome-bugbounty-tools
A curated list of various bug bounty tools
ashishb/android-security-awesome
A collection of android security related resources
edoardottt/awesome-hacker-search-engines
A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more
qazbnm456/awesome-web-security
πΆ A curated list of Web Security materials and resources.