Skip to content

NodeSecure/scanner

Repository files navigation

# Nodesecure Scanner

version maintained OpenSSF Scorecard mit build

⚡️ Run a static analysis of your module's dependencies.

💡 Features

Scanner builds on JS-X-Ray (SAST) and Vulnera (CVE detection), and adds additional detections such as:

  • Detects:
  • Highlights packages by name, version(s), or maintainer
  • Highlights infrastructure components such as ip, hostname, email, url
  • Supports NPM and Yarn lockfiles

💃 Getting Started

$ npm i @nodesecure/scanner
# or
$ yarn add @nodesecure/scanner

For full API documentation, options, and usage examples, see the @nodesecure/scanner package README.

Workspaces

🐥 Contributors guide

If you are a developer looking to contribute to the project, you must first read the CONTRIBUTING guide.

Once you have finished your development, check that the tests (and linter) are still good by running the following script:

$ npm run check

Caution

In case you introduce a new feature or fix a bug, make sure to include tests for it as well.

Contributors ✨

All Contributors

Thanks goes to these wonderful people (emoji key):

Gentilhomme
Gentilhomme

💻 📖 👀 🛡️ 🐛
Tony Gorez
Tony Gorez

💻 📖 👀 🐛
Haze
Haze

💻
Maksim Balabash
Maksim Balabash

💻 🐛
Antoine Coulon
Antoine Coulon

💻 🐛 👀 🚧 🛡️
Nicolas Hallaert
Nicolas Hallaert

💻
Yefis
Yefis

💻
Franck Hallaert
Franck Hallaert

💻
Ange TEKEU
Ange TEKEU

💻
Vincent Dhennin
Vincent Dhennin

💻 📖 👀 🐛
Kouadio Fabrice Nguessan
Kouadio Fabrice Nguessan

🚧
PierreDemailly
PierreDemailly

💻 👀 🐛 ⚠️
Kishore
Kishore

💻 📖
Clement Gombauld
Clement Gombauld

💻
Ajāy
Ajāy

💻 📖
Nicolas Hallaert
Nicolas Hallaert

📖
Maxime
Maxime

⚠️
Ange TEKEU
Ange TEKEU

💻
Alexandre Malaj
Alexandre Malaj

💻 📖 🌍
FredGuiou
FredGuiou

🚧
Christian Lisangola
Christian Lisangola

⚠️
Quentin Lepateley
Quentin Lepateley

📖
Antoine Neff
Antoine Neff

🌍
Kévin VOYER
Kévin VOYER

🌍
Mathieu
Mathieu

💻 🌍
im_codebreaker
im_codebreaker

💻 📖 🎨
Ayushmaan Shrotriya
Ayushmaan Shrotriya

📖
Inès & Mélu
Inès & Mélu

📖
zwOk9
zwOk9

⚠️
Pierre Martin
Pierre Martin

📖
Hamed Mohamed
Hamed Mohamed

💻

License

MIT

About

⚡️ A package API to run a static analysis of your module's dependencies. This is the CLI engine!

Topics

Resources

License

Contributing

Security policy

Stars

Watchers

Forks

Contributors

Languages