The goal of this project is to provide additional features on top of the existing npm audit options
-
Updated
Jul 20, 2026 - TypeScript
The goal of this project is to provide additional features on top of the existing npm audit options
EZGHSA is a command-line tool for summarizing and filtering vulnerability alerts on Github repositories.
A tool to audit Hex dependencies, to make sure your ✨ gleam projects really sparkle!
A collection of packages for using security advisories from osv.dev in Node.js.
23-tool MCP server for CVE & vulnerability intelligence. NVD, EPSS, CISA KEV, GitHub Advisory, OSV — unified in one server. Risk scoring, bulk triage, exploit search. 2 dependencies, runs with npx.
Public Codespaces runner for verified CVE/GHSA vulnerability reproductions
Security Knowledge Graph Triples
Self-hosted Grafana dashboard for GitHub Security Advisories. Postgres-backed, mirrors the GitHub API 1:1.
A practical, consult-as-you-go guide for open source maintainers handling GitHub security advisories. Triage, private forks, CVEs, publication, and the gotchas nobody warns you about.
Lightweight, dependency-free shell script that scans 12 ecosystems (npm, PyPI, Go, Rust, Maven/Gradle, NuGet, RubyGems, Composer, Pub, Hex, Swift, GitHub Actions) for vulnerable dependencies using OSV & GHSA feeds — or your own JSON / CSV / PURL / SBOM / SARIF / Trivy sources
Shell script to detect TanStack npm supply chain attack indicators (CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx)
Broken Object Level Authorization (BOLA) enables cross-user document viewing, modification, and unauthorized deletion via direct object reference.
Broken Object Level Authorization (BOLA) combined with credentialed CORS misconfiguration enables cross-user, cross-origin authenticated document exfiltration.
Vulnerability alerts for the things you actually run: correlates GHSA + NVD against your dependency tree, scores every advisory from its CVSS vector, and pushes only what affects an installed version.
CLI tool that scans pnpm overrides and determines whether CVE-related overrides can be safely removed by running pnpm audit
GHSA-j425-whc4-4jgc: OpenClaw system.run Env Override Filtering Allowed Dangerous Helper-Command Pivots (CVSS 6.3)
CVE-2026-50181 / GHSA-fg23-3346-88f5: Langroid path traversal advisory landing page
CVE-2026-50131 / GHSA-xw9q-2mv6-9fr8: Fedify incomplete SSRF mitigation advisory landing page
Independent AI/LLM security research — 10 shipped fixes, 5 GHSA advisories; focus on multi-tenant isolation, MCP protocol attack surface, SSRF/cookie boundary leakage
CVE-2026-54520 / GHSA-cm8g-8jfq-887p: ai-agent-automation workflow path traversal advisory landing page
To associate your repository with the ghsa topic, visit your repo's landing page and select "manage topics."