This release adds 2 notable features for engineering teams evaluating rollout.
Published 22d
Vulnerability Scanning
✓ No known CVEs patched
✓ No known CVEs patched in this version
Topics
security
cve
javascript
nodejs
owasp
security-tools
Summary
AI summaryGitHub Action now supports --usage, --only-used, --sarif, and defaults no-cache to true in CI.
Full changelog
Added
- GitHub Action now exposes
--usage,--only-used,--sarif, and--no-cacheinputs. Theno-cacheinput defaults totruein CI since runners are ephemeral. --sarifflag writes a SARIF 2.1.0 file to the current directory for upload to GitHub Code Scanning. One result per CVE, rules deduplicated, severity mapped to SARIF levels.
Validation
- npm test
- npm run build
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About OWASP/cve-lite-cli
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]