npm Dependency Audit Scanner
Scans Node.js projects for vulnerable dependencies using npm audit and the OSV.dev REST API. Cross-references CVE databases via the National Vulnerability Database API v2.0 and generates SBOM documents in CycloneDX format.
Installation
Use the upstream install or setup path that matches your environment:
- npm Docs
- npm package scope, access level, and visibility
- Docker and private modules
- npm License
Requirements and caveats from upstream:
- Downloading and installing Node.js and npm
- Try the latest stable version of node
- Creating Node.js modules
Basic usage or getting-started notes:
Creating a strong password
Receiving a one-time password over email
About two-factor authentication
Source: https://docs.npmjs.com/auditing-package-dependencies-for-security-vulnerabilities/