Skip to the content.

npm version license ossf scorecard slsa level3 github ci workflow codecov

A Node.js tool that performs a static and deep analysis of a packageโ€™s dependency tree: AST-based scanning for malicious or unsafe patterns, npm registry metadata, license conformance, vulnerability aggregation (GitHub Advisory, Sonatype, Snyk) and OpenSSF Scorecard, all rendered through an interactive dependency graph.

๐Ÿ’ƒ Getting Started

$ npm install @nodesecure/cli -g
$ nsecure auto express

This repository is a monorepo. The @nodesecure/cli package, along with its full feature list, command documentation, configuration and FAQ, lives in the workspaces/cli workspace โ€” head there for everything about installing and using the CLI.

๐Ÿ“ฆ Workspaces

name package and link
cli @nodesecure/cli
documentation-ui @nodesecure/documentation-ui
vis-network @nodesecure/vis-network
size-satisfies @nodesecure/size-satisfies
server @nodesecure/server
cache @nodesecure/cache

These packages are available in the Node Package Repository and can be easily installed with npm or yarn, for example:

$ npm i @nodesecure/documentation-ui
# or
$ yarn add @nodesecure/documentation-ui

๐Ÿ™ Contributing

If you are a developer looking to contribute to the project, please first read our CONTRIBUTING guide (Code of Conduct, first-contributor guide, Developerโ€™s Certificate of Origin, Discord).

Local Setup

$ git clone https://github.com/NodeSecure/cli.git
$ cd cli

$ npm install
# bundle/compile front-end assets for every workspace
$ npm run build

[!IMPORTANT] Restart npm run build when modifying files under a workspaceโ€™s public/front-end assets folder.

Once you have finished your development, check that the tests (and linter) are still good by running the following script:

$ npm test

[!CAUTION] If you add a feature, try adding tests for it along.

Publishing package and SLSA

The @nodesecure/cli package is published on NPM with provenance, ensuring that this project is compliant with SLSA Level 3 standards. The build and publication process is managed through the GitHub npm-provenance.yml workflow, which is automatically triggered upon the creation of a new release.

To create a local version of the package using npm and Git, follow these commands:

$ npm version [patch | minor | major]
$ git commit -am "chore: x.x.x"
$ git push origin master --tags

These commands will increment the package version, commit the changes, and push them along with the tags to the repository.

Contributors โœจ

All Contributors

Thanks goes to these wonderful people (emoji key):

Haze
Haze

๐Ÿ’ป ๐ŸŽจ
fraxken
fraxken

๐Ÿ’ป ๐Ÿ› ๐Ÿ“ โš ๏ธ ๐Ÿ“– ๐ŸŽจ
Xavier Stouder
Xavier Stouder

๐Ÿ’ป ๐ŸŽจ ๐Ÿ“–
Tony Gorez
Tony Gorez

๐Ÿ’ป ๐Ÿ“– ๐Ÿ‘€
abdellah-housni
abdellah-housni

๐Ÿ›
Vincent Dhennin
Vincent Dhennin

๐Ÿ’ป ๐Ÿ›
halcin
halcin

๐Ÿ’ป
Ange TEKEU
Ange TEKEU

๐Ÿ’ป
PierreDemailly
PierreDemailly

๐Ÿ’ป
Inรจs & Mรฉlusine LUJAN-ALVAREZ
Inรจs & Mรฉlusine LUJAN-ALVAREZ

๐Ÿ’ป
Yefis
Yefis

๐Ÿ’ป
Kouadio Fabrice Nguessan
Kouadio Fabrice Nguessan

๐Ÿšง
Kishore
Kishore

๐Ÿ’ป
FredGuiou
FredGuiou

๐Ÿ’ป
ZakariaEttani
ZakariaEttani

๐Ÿ’ป
Foucart Julien
Foucart Julien

๐Ÿ“–
Dafyh
Dafyh

โš ๏ธ
Clement Gombauld
Clement Gombauld

๐Ÿ’ป
Mark MALAJ
Mark MALAJ

๐Ÿ›
Younes Iddahamou Idrissi
Younes Iddahamou Idrissi

๐Ÿ’ป
zeearth
zeearth

๐Ÿ’ป

This project follows the all-contributors specification. Contributions of any kind welcome!

License

MIT