The goal of this project is to provide additional features on top of the existing npm audit options
-
Updated
Jan 21, 2026 - TypeScript
The goal of this project is to provide additional features on top of the existing npm audit options
EZGHSA is a command-line tool for summarizing and filtering vulnerability alerts on Github repositories.
A tool to audit Erlang & Elixir dependencies, to make sure your ✨ gleam projects really sparkle!
A collection of packages for using GitHub security advisories in Node.js.
A lightweight shell script that scans node / bun / deno projects to detect vulnerable npm packages using OSV and GHSA vulnerabilities database or custom source formats (JSON / CSV / PURL / SBOM / SARIF / TRIVY)
CLI tool that scans pnpm overrides and determines whether CVE-related overrides can be safely removed by running pnpm audit
📦 Better NPM Audit drop in replacement. Always mirrors the latest version. Patched to behave more consistently in `offline=true` environments and be slightly less verbose. — `npm install better-npm-audit@github:EIGHTFINITE/better-npm-audit#main` — https://github.com/EIGHTFINITE/better-npm-audit/tags | https://github.com/jeemok/better-npm-audit
Broken Object Level Authorization (BOLA) enables cross-user document viewing, modification, and unauthorized deletion via direct object reference.
Broken Object Level Authorization (BOLA) combined with credentialed CORS misconfiguration enables cross-user, cross-origin authenticated document exfiltration.
No limit rest api for github advisory database
CVE-2026-32885: ZipSlip Path Traversal in ddev/ddev Archive Extraction (CVSS 6.5 Moderate)
CVE-2026-32809: Unvalidated Symlink Targets in Tar Extraction in ouch-org/ouch (CVSS 7.4 High)
GHSA-j425-whc4-4jgc: OpenClaw system.run Env Override Filtering Allowed Dangerous Helper-Command Pivots (CVSS 6.3)
The npm audit assistant
CVE-2026-33693: SSRF via 0.0.0.0 Bypass in activitypub-federation-rust v4_is_invalid() (CVSS 6.5 Moderate)
Convert GitHub and HackerOne security reports into structured skills for automated code audits and penetration testing using Claude AI.
Add a description, image, and links to the ghsa topic page so that developers can more easily learn about it.
To associate your repository with the ghsa topic, visit your repo's landing page and select "manage topics."