logo

CVE Lite CLI: Open-source dependency vulnerability scanner

ID: f5035047-b603-569d-8d0e-01d07d4b43ed

STIX ID: report--f5035047-b603-569d-8d0e-01d07d4b43ed

Feed Name: Help Net Security

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Mirko Zorz

...
...

This article describes CVE Lite CLI, an open-source OWASP Incubator tool that performs fast local dependency vulnerability scans for JavaScript and TypeScript projects by reading lockfiles and querying the OSV database; it highlights features like direct vs transitive dependency identification, copy-and-run fix commands for multiple package managers, offline/adaptable use for air-gapped environments, SARIF output for CI integration, and plans for future enhancements.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.