npm

Search results

85 packages found

Evidence-driven repo intelligence: DORA metrics, forensic signals, vulnerability scan, and delivery verdict for any GitHub repo. One command, no setup.

published version 1.7.0, 2 months ago0 dependents licensed under $MIT
335,095

OSV vulnerability scanner for Bun projects

published version 1.0.0, 7 months ago0 dependents licensed under $MIT
16,723

Audit Yarn v1 lockfiles against the OSV vulnerability database

published version 0.1.8, 2 months ago0 dependents licensed under $MIT
15,596

Developer-friendly CLI for scanning JS/TS projects for dependency vulnerabilities using local lockfiles and OSV

published version 1.23.0, a day ago0 dependents licensed under $MIT
6,602

Vulnerability scanner for Bun projects

published version 1.1.2, 2 months ago0 dependents licensed under $MIT
3,457

Audit, secure, and clean up package manager overrides for npm, pnpm, Yarn, and Bun.

published version 1.12.5, 15 hours ago0 dependents licensed under $MIT
2,519

In-app dev companion for React. Floating button + drawer with viewport switcher, route map, SEO/Performance/Tracker checks and dependency vulnerability scanning. Zero config in dev, invisible in production.

published version 0.2.6, 20 days ago0 dependents licensed under $MIT
1,690

DataNexus MCP — AI-Ready public data intelligence. 55 tools: CVE risk verdicts, SBOM licence policy, frontend security (manifest audit, CI scanner, typosquatting), licence compatibility, nonprofit 990 trends, SBOM monitoring, federal contracts, NPI lookup

published version 2.4.9, 3 days ago0 dependents licensed under $SEE LICENSE IN LICENSE
2,278

OpenCodeHub — Priority-1 scanner wrappers (semgrep, betterleaks, osv-scanner, bandit, biome)

published version 0.2.4, 13 days ago1 dependents licensed under $Apache-2.0
1,374

Scan ALL Maven, npm, Yarn, Composer, Python, C#/.NET, Go & Ruby dependencies — plus embedded JARs (fat-jars/war/ear) — in a source tree ONE SHOT without mvn/python/etc — CVE (EPSS/KEV-prioritised), EOL, obsolete, outdated & licenses, with SBOM/CSAF/SARIF/

published version 2.2.4, 10 days ago0 dependents licensed under $MIT
1,637

Dependency install safety gate with OSV-backed advisory checks, approved-spec ledger enforcement, and reorg rollback hooks

published version 2.6.1, 8 days ago0 dependents licensed under $Apache-2.0
1,350

IRM key exchange module for Open Secure Viewer — RSA-4096 + AES-GCM WebCrypto

published version 9.1.0, 19 days ago0 dependents licensed under $MIT
1,952

React components and hooks for @open-secure-viewer/core secure PDF/Office viewer. Drop-in replacement for Apryse WebViewer React integration.

published version 9.0.2, 19 days ago0 dependents licensed under $Apache-2.0
1,669

Standalone, zero-dependency CLI for npm supply chain security analysis — vulnerability scanning, OpenSSF Scorecard, install-script detection, publisher history, and more.

published version 1.10.0, 12 days ago0 dependents licensed under $Apache-2.0
1,010

One-command security scanner for AI-generated code. Vibe coded. Vibe hardened.

published version 0.4.0, a month ago0 dependents licensed under $MIT
996

React hooks for the OSV (Open Source Vulnerabilities) API, built on @tanstack/react-query

published version 1.5.1, 6 days ago0 dependents licensed under $MIT
806

DOCX and XLSX renderers for @open-secure-viewer/core. Powered by docx-preview and SheetJS.

published version 2.1.3, 19 days ago0 dependents licensed under $Apache-2.0
1,246

Supply-chain security firewall for Node.js — resolves dependencies, scans via OSV.dev and NVD, and enforces configurable vulnerability policies before anything reaches node_modules.

published version 0.3.0, 25 days ago0 dependents licensed under $SEE LICENSE IN LICENSE.md
1,023

Nexus Dependency Auditor — OSV CVE scanning, offline cache, supply chain risk analysis, and build-time blocking

published version 0.9.32, 5 days ago2 dependents licensed under $MIT
919

Query OSV.dev for package vulnerabilities, batch-audit dependency lists, and fetch full advisory records via MCP. STDIO or Streamable HTTP.

published version 0.1.5, 2 days ago0 dependents licensed under $Apache-2.0
777