Skip to content

OWASP/cve-lite-cli

v1.21.0 Feature

This release adds 1 notable feature for engineering teams evaluating rollout.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

security cve javascript nodejs owasp security-tools

Summary

AI summary

Ratcheting mode adds automatic baseline suppression of known CVEs

Changes in this release

Feature Low

Adds ratcheting mode to suppress known CVE findings and report only new ones.

Adds ratcheting mode to suppress known CVE findings and report only new ones.

Source: llm_adapter@2026-06-09

Confidence: high

Full changelog

Added

  • Ratcheting mode: run cve-lite . --ratchet once to snapshot current findings into .cve-lite/baseline.json. All subsequent scans automatically suppress known findings and only report new ones introduced above the baseline. No CI flag changes needed - the baseline file's presence activates suppression.

Docs

  • New dedicated Ratcheting Mode page
  • MAL- advisory handling and unverifiable private source findings documented in how-remediation-works

Validation

  • npm test
  • npm run build

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track OWASP/cve-lite-cli

Get notified when new releases ship.

Sign up free

About OWASP/cve-lite-cli

All releases →

Beta — feedback welcome: [email protected]