Scan dependencies for vulnerabilities. RTFM.
npm install rtfm-depcheckScan your dependencies for known vulnerabilities. Fast. Simple. RTFM.
``bash`
npm install -g depcheck-cli
`bashScan current directory
depcheck
Output
`
$ depcheck Scanning package.json...
Found 2 vulnerabilities:
✗ minimist@1.2.0
Severity: CRITICAL
CVE: CVE-2021-44906
Issue: Prototype Pollution
Fix: upgrade to >=1.2.6
✗ lodash@4.17.15
Severity: HIGH
CVE: CVE-2021-23337
Issue: Command Injection
Fix: upgrade to >=4.17.21
Summary: 1 critical, 1 high, 0 medium, 0 low
Run 'npm update' to fix vulnerabilities
`Exit codes
-
0 - No vulnerabilities found
- 1` - Vulnerabilities found or errorMIT
---
rtfm.codes - read the fine manual