This release adds 2 notable features for engineering teams evaluating rollout.
Published 1mo
Vulnerability Scanning
✓ No known CVEs patched
✓ No known CVEs patched in this version
Topics
security
cve
javascript
nodejs
owasp
security-tools
Summary
AI summaryAdded conservative --fix mode for validated direct dependency remediation.
Full changelog
Highlights
- added conservative --fix mode for validated direct dependency remediation
- --fix now applies package-manager-native direct updates, rescans automatically, and prints concise applied/skipped summary
- added dedicated --fix docs and updated website guidance
- refreshed OWASP Juice Shop case study with --fix evidence snapshot
- clarified README comparison table with explicit auto-fix support notes
Validation
- npm test
- npm run build
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About OWASP/cve-lite-cli
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]