npm Audit Dependency Report Generator
Generates comprehensive vulnerability reports from npm audit JSON output and the OSV (Open Source Vulnerabilities) API. Parses npm audit --json results, enriches each CVE with CVSS scores from the NVD REST API, and groups findings by severity. Produces SARIF output compatible with GitHub Advanced Security.
Installation
Use the upstream install or setup path that matches your environment:
- npm-audit | npm Docs Skip to search Skip to content
- npm Docs
- npm package scope, access level, and visibility
- Docker and private modules
Requirements and caveats from upstream:
- Downloading and installing Node.js and npm
- Try the latest stable version of node
- Creating Node.js modules
Basic usage or getting-started notes:
Creating a strong password
Receiving a one-time password over email
About two-factor authentication