CVE Lite CLI: Open-source dependency vulnerability scanner
ID: f5035047-b603-569d-8d0e-01d07d4b43ed
STIX ID: report--f5035047-b603-569d-8d0e-01d07d4b43ed
Feed Name: Help Net Security
This article describes CVE Lite CLI, an open-source OWASP Incubator tool that performs fast local dependency vulnerability scans for JavaScript and TypeScript projects by reading lockfiles and querying the OSV database; it highlights features like direct vs transitive dependency identification, copy-and-run fix commands for multiple package managers, offline/adaptable use for air-gapped environments, SARIF output for CI integration, and plans for future enhancements.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
