CVE Lite CLI is an OWASP Foundation project that scans JavaScript and TypeScript lockfiles locally on a developer's machine. It identifies vulnerabilities, explains dependency paths and reachability, and provides copy-and-run fix commands along with batched PR suggestions. Designed for fast local feedback loops, it requires no account, no cloud, and runs entirely offline while supporting npm, pnpm, Yarn, and Bun.
In the CLI tools & terminal space, CVE Lite CLI takes a focused approach. Finding, understanding, and fixing vulnerable dependencies in JS/TS lockfiles without relying on cloud services or CI pipelines. It is built as an open-source project for developers. The project is open source (MIT). It ships for the command line, and it can be self-hosted.
Behind CVE Lite CLI is OWASP Foundation, based in the United States, and it first shipped in 2026. The project is developed in the open on GitHub with 646 stars and 319 commits in the last 90 days. Among its 7 catalogued features are offline scans, auto-fix, and reachability analysis.
Summary written by a language model from the project’s public pages.
What PulseGate has recorded for this listing
Same category — not a similarity match