World Congress 2025

Friend or Foe? TypeScript Security Fallacies

July 10, 2025 17:30 – 18:00 · 30 min Stage 1
design patterns cybersecurity typescript

What this session covers

So TypeScript has become the de facto industry standard for developing web applications these days and promising type security, but do developers properly understand the role it plays in securing applications and does the type safety promise hold true in face of real-world security threats?

Developers often mistake dev-time vs runtime security as well as confuse test cases for security guard rails. Can TypeScript actually provide you with code security benefits? In this session we will explore insecure TypeScript patterns, learn how HTTP parameter pollution vulnerabilities impact TypeScript code bases and witness first-hand how attackers employ prototype pollution attacks that cripple codebases even when developers use schema validation libraries like Zod. Through hands-on coding we’ll hack a TypeScript application and learn security best practices.

Related talks at this congress

Open session

World Congress 2025

July 10, 2025 · 10:30–12:30

M7 (18 Seats)

Code Red: When Your Tools Turn Against You

Aaron Bray, Julian Totzek-Hallhuber

Aaron Bray
Julian Totzek-Hallhuber
Open session

World Congress 2025

July 11, 2025 · 10:20–10:50

Stage 5

End-to-End TypeScript: Completing the Modern Development Stack

Marco Podien

Senior Developer Relations Advocate, Algorand Foundation

Marco Podien
Open session

World Congress 2025

July 11, 2025 · 14:20–14:50

Stage 3 - Microsoft

Real-World Security for Busy Developers

Kevin Lewis

Senior Developer Advocate at GitHub

Kevin Lewis
Open session

World Congress 2025

July 10, 2025 · 14:50–15:20

Stage 11

Best of the Worst – the most awful anti-features in JavaScript, ranked!

Peter Kröner

Webtechnologie-Erklärbär

Peter Kröner
All sessions at this congress