The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how to effectively address them.
active 2025-06-13 → 2026-08-04 (UTC)
Activity over time
Daily event counts in the loaded window
Line chart, 418 days from 2025-06-13 to 2026-08-04. Pushes: 17 total, peak 4 in a day. Pull requests: 35 total, peak 18 in a day. Issues: 0 total, peak 0 in a day. Comments: 20 total, peak 7 in a day. Stars: 0 total, peak 0 in a day.
- Pushes
- Pull requests
- Issues
- Comments
- Stars
Stars, PRs, issues and forks are under-captured in the later part of this window. GH Archive progressively stopped capturing non-push events during 2026 — −95% or worse by the end of the window. Every series here except Pushes fades for that reason, so a decline above reflects the archive, not this repository. Pushes stay reliable throughout, so read them, and the contributor counts derived from them, as the real signal. Data health has the measurements.
Top contributors
Pushes, PRs, issues, reviews and comments — stars and forks excluded, so this is contribution rather than popularity
| Contributor | Contributions | Pushes | PRs | Comments |
|---|---|---|---|---|
| snyk-io[bot] | 15 | 6 | 4 | 5 |
| ac-vinayak-agrawal | 15 | 2 | 13 | 0 |
| dependabot[bot] | 13 | 0 | 10 | 3 |
| Linish2020 | 8 | 0 | 8 | 0 |
| sonarqubecloud[bot] | 8 | 0 | 0 | 8 |
| AC-KunalParmar | 7 | 7 | 0 | 0 |
| socket-security[bot] | 4 | 0 | 0 | 4 |
| ac-tusharmeshram | 1 | 1 | 0 | 0 |
| semgrep-app[bot] | 1 | 1 | 0 | 0 |
Recent activity
Latest issues, pull requests and releases
- Pull request#75snyk-io[bot]2026-03-27 22:48
- Issue comment#73snyk-io[bot]2026-03-10 08:42Checkmarx Bot - Auto Pull Request in branch "master"
- Issue comment#72snyk-io[bot]2026-03-03 22:59[Snyk] Security upgrade underscore from 1.9.1 to 1.13.8
- Issue comment#71sonarqubecloud[bot]2026-03-03 22:58[Snyk] Security upgrade underscore from 1.13.7 to 1.13.8
- Issue comment#69sonarqubecloud[bot]2026-02-26 19:46[Snyk] Security upgrade forever from 2.0.0 to 3.0.4
- Issue comment#68snyk-io[bot]2026-02-20 07:20[Snyk] Security upgrade forever from 2.0.0 to 3.0.4
- Pull request#68snyk-io[bot]2026-02-20 07:20
- Issue comment#66sonarqubecloud[bot]2026-02-18 07:25[Snyk] Fix for 1 vulnerabilities
- Issue comment#66snyk-io[bot]2026-02-18 07:25[Snyk] Fix for 1 vulnerabilities
- Pull request#66snyk-io[bot]2026-02-18 07:25
- Pull request#61dependabot[bot]2026-02-18 07:24
- Issue comment#64sonarqubecloud[bot]2026-02-13 07:13[Snyk] Fix for 1 vulnerabilities
- Issue comment#64snyk-io[bot]2026-02-13 00:13[Snyk] Fix for 1 vulnerabilities
- Pull request#63snyk-io[bot]2025-12-30 15:25
- Issue comment#57sonarqubecloud[bot]2025-11-03 10:21Bump the npm_and_yarn group across 1 directory with 15 updates
- Issue comment#61sonarqubecloud[bot]2025-11-03 10:21Bump the npm_and_yarn group across 1 directory with 18 updates
- Issue comment#60sonarqubecloud[bot]2025-11-03 10:21Bump the npm_and_yarn group across 1 directory with 17 updates
- Issue comment#62sonarqubecloud[bot]2025-11-03 10:21Update index.js
- Issue comment#59socket-security[bot]2025-10-08 09:09Bump the npm_and_yarn group across 1 directory with 14 updates
- Pull request#61dependabot[bot]2025-10-08 09:08
- Issue comment#56socket-security[bot]2025-10-08 09:08Bump the npm_and_yarn group across 1 directory with 15 updates
- Pull request#58dependabot[bot]2025-10-08 09:08
- Pull request#55dependabot[bot]2025-10-08 09:07
- Pull request#59dependabot[bot]2025-10-08 09:07
- Issue comment#55dependabot[bot]2025-10-08 09:07Bump debug from 3.2.6 to 3.2.7 in the npm_and_yarn group across 1 directory
Totals cover only the window loaded into ClickHouse and count events, not GitHub's lifetime totals — 0 stars here means stars gained during the window, not the repo's star count.