Skip to content

OWASP/cve-lite-cli

Vulnerability Scanning

A terminal‑based vulnerability scanner that scans lockfiles and provides ready‑to‑run fix commands for CI pipelines

TypeScript Latest v1.28.0 · 14h ago Security brief →

Features

  • Scans project dependency lockfiles directly from the terminal
  • Generates actionable, copy‑and‑run fix commands rather than just CVE IDs
  • Runs entirely locally – no source code or dependency tree leaves your machine
  • Supports multiple package managers (npm, pnpm, Yarn, Bun)
  • Offers detailed reporting formats (JSON, SARIF, interactive HTML)

Recent releases

View all 50 releases →
No immediate action
v1.28.0 Breaking risk

Cooldown resolver + maintenance risk

No immediate action
v1.27.0 Breaking risk

Theme toggle + stale-floor detection

No immediate action
v1.26.0 New feature

Scheduled security fix PRs

Review required
v1.25.0 New feature
Dependencies

Override hygiene audit + fix

No immediate action
v1.24.0 New feature

SARIF + HTML reports

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
639
Forks
108
Languages
TypeScript MDX JavaScript
Downloads/week
3,739 ↑190%
NPM Maintainers
1
Contributors
38

Install & Platforms

Install via
npm

Community & Support

Beta — feedback welcome: [email protected]