The goal of this project is to provide additional features on top of the existing npm audit options
-
Updated
Jul 20, 2026 - TypeScript
The goal of this project is to provide additional features on top of the existing npm audit options
EZGHSA is a command-line tool for summarizing and filtering vulnerability alerts on Github repositories.
23-tool MCP server for CVE & vulnerability intelligence. NVD, EPSS, CISA KEV, GitHub Advisory, OSV — unified in one server. Risk scoring, bulk triage, exploit search. 2 dependencies, runs with npx.
A tool to audit Hex dependencies, to make sure your ✨ gleam projects really sparkle!
A collection of packages for using security advisories from osv.dev in Node.js.
Public Codespaces runner for verified CVE/GHSA vulnerability reproductions
Self-hosted Grafana dashboard for GitHub Security Advisories. Postgres-backed, mirrors the GitHub API 1:1.
Security Knowledge Graph Triples
A practical, consult-as-you-go guide for open source maintainers handling GitHub security advisories. Triage, private forks, CVEs, publication, and the gotchas nobody warns you about.
Lightweight, dependency-free shell script that scans 12 ecosystems (npm, PyPI, Go, Rust, Maven/Gradle, NuGet, RubyGems, Composer, Pub, Hex, Swift, GitHub Actions) for vulnerable dependencies using OSV & GHSA feeds — or your own JSON / CSV / PURL / SBOM / SARIF / Trivy sources
Broken Object Level Authorization (BOLA) enables cross-user document viewing, modification, and unauthorized deletion via direct object reference.
Broken Object Level Authorization (BOLA) combined with credentialed CORS misconfiguration enables cross-user, cross-origin authenticated document exfiltration.
CLI tool that scans pnpm overrides and determines whether CVE-related overrides can be safely removed by running pnpm audit
Shell script to detect TanStack npm supply chain attack indicators (CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx)
Vulnerability alerts for the things you actually run: correlates GHSA + NVD against your dependency tree, scores every advisory from its CVSS vector, and pushes only what affects an installed version.
Claude Code skill for auditing web apps for security vulnerabilities. Detects inside-codebase vs outside-black-box, runs the right checklist, sweeps server/infra, deep-dives rate-limit posture. 14 PoC probe templates + deep ripgrep recipes.
CVE-2026-50181 / GHSA-fg23-3346-88f5: Langroid path traversal advisory landing page
CVE-2026-50131 / GHSA-xw9q-2mv6-9fr8: Fedify incomplete SSRF mitigation advisory landing page
GHSA-j425-whc4-4jgc: OpenClaw system.run Env Override Filtering Allowed Dangerous Helper-Command Pivots (CVSS 6.3)
Independent AI/LLM security research — 10 shipped fixes, 5 GHSA advisories; focus on multi-tenant isolation, MCP protocol attack surface, SSRF/cookie boundary leakage
To associate your repository with the ghsa topic, visit your repo's landing page and select "manage topics."