JavaScript/TypeScript Dependency Scanner — An OWASP Foundation Project Scan. Understand. Fix. Most security tools are built around pipelines, not developers. CVE Lite CLI scans your lockfile locally in seconds, explains the dependency path, and tells you what to update before you push. View on GitHub View on npm GitHub Action No account required npm, pnpm, Yarn, and Bun lockfile support Usage-aware reachability scanning Offline scans with local advisory DB Copy-and-run direct fix commands Parent-aware transitive guidance Conservative auto-remediation with --fix Built-in AI assistant skills Free Free to use No account, no subscription, no cloud required Local Runs locally Nothing leaves your machine Fast Fast Results in seconds, rescans near-instant
Most security tools are built around pipelines, not developers. CVE Lite CLI scans your lockfile locally in seconds, explains the dependency path, and tells you what to update before you push. View on GitHub View on npm GitHub Action No account required npm, pnpm, Yarn, and Bun lockfile support Usage-aware reachability scanning Offline scans with local advisory DB Copy-and-run direct fix commands Parent-aware transitive guidance Conservative auto-remediation with --fix Built-in AI assistant skills Free Free to use No account, no subscription, no cloud required Local Runs locally Nothing leaves your machine Fast Fast Results in seconds, rescans near-instant
Covered worldwide ReversingLabs DevOps.com View all press →
Scans your lockfile on your machine. No hosted account or cloud dashboard required.
Prioritizes copy-and-run commands instead of leaving you with raw CVE IDs.
Run a scan, apply the suggested command, rescan immediately, and keep moving without waiting on CI.
Parent-aware remediation Fix the package that controls the vulnerable dependency path. Transitive CVEs are easy to mishandle. CVE Lite CLI avoids recommending direct installs for packages that are only present transitively and points at the parent package instead.
Transitive CVEs are easy to mishandle. CVE Lite CLI avoids recommending direct installs for packages that are only present transitively and points at the parent package instead.
For npm lockfiles, the CLI checks whether a known non-vulnerable child can be resolved inside the current parent range first.
Workspace-local package context is preserved so hoisted npm packages can still map back to their logical parent chain.
Read the remediation strategy to see when the CLI recommends direct upgrades, parent updates, or parent upgrades.
Guides Go deeper when you need the details. Learn how CVE Lite CLI builds reports, handles restricted networks, compares with common scanners, and behaves across package-manager lockfiles.
Learn how CVE Lite CLI builds reports, handles restricted networks, compares with common scanners, and behaves across package-manager lockfiles.
Generate a self-contained dashboard with severity cards, searchable findings, and copy-ready fix commands. Read the guide .
Sync OSV data locally and scan restricted environments without runtime advisory API calls. Read the guide .
See how CVE Lite CLI compares with Dependabot, npm audit, OSV-Scanner, Snyk, and Socket. Compare tools .
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
