PulseGateIndexCategoriesUpdatesLive intelligence on AI-era software— indexed in the last hour
Coverage—projects tracked
Freshness—newest entry
Cadence—last week average · — today
Index9 markets86 categories
PulseGate

Live intelligence on the AI-era software market — apps, models, agents and infrastructure.

Most of it never reaches an official store. PulseGate maps the whole market — every category, worldwide — and measures how it moves: what’s launching, what’s gaining, what’s going quiet.

FollowGitHubX (Twitter)LinkedIn
Platform
All AppsFull IndexCategoriesIndustry UpdatesData SourcesCoverage RulesGlossaryEmbed Widget
Support
Help CenterSubmit your projectReport an Issue
Company
AboutDimaxiaPress & DataContactPlatform Status
Legal
PrivacyTermsDisclaimer
Dimaxia · Dymaxio s.r.o. · Prague, Czechia · © 2026WatchlistSitemapSystem status
PulseGateCLCVE Lite CLI
Visit↗
Skip to content
  1. Index›
  2. CLI tools & terminal›
  3. CVE Lite CLI
← Back to the index
CL

CVE Lite CLI

owasp.org·Infrastructure·🇺🇸

CVE Lite CLI is an OWASP Foundation project that scans JavaScript and TypeScript lockfiles locally on a developer's machine. It identifies vulnerabilities, explains dependency paths and reachability, and provides copy-and-run fix commands along with batched PR suggestions. Designed for fast local feedback loops, it requires no account, no cloud, and runs entirely offline while supporting npm, pnpm, Yarn, and Bun.

Open SourceMITCLISelf-hosted
CCVE Lite CLI preview
Visit owasp.org↗
646stars
116forks
7features
2026since

Overview

7 features

In the CLI tools & terminal space, CVE Lite CLI takes a focused approach. Finding, understanding, and fixing vulnerable dependencies in JS/TS lockfiles without relying on cloud services or CI pipelines. It is built as an open-source project for developers. The project is open source (MIT). It ships for the command line, and it can be self-hosted.

Behind CVE Lite CLI is OWASP Foundation, based in the United States, and it first shipped in 2026. The project is developed in the open on GitHub with 646 stars and 319 commits in the last 90 days. Among its 7 catalogued features are offline scans, auto-fix, and reachability analysis.

Summary written by a language model from the project’s public pages.

  • ✓Offline scans
  • ✓Auto-fix
  • ✓Reachability analysis
  • ✓Transitive guidance
  • ✓Batched fix PRs
  • ✓HTML reports
  • ✓Verbose output
Tags
vulnerability-scannerdependency-auditlockfile-scanningjs-ts-securityoffline-scanner

Built with & integrations

Hosting
Cloudflare
Runs on
CLISelf-hosted
Detected from
Cloudflare
cf-ray header · cf-cache-status header

Trust & compliance

License
MIT
Verified signals
✓HTTPS✓Open Source✓Free tier✓GitHub · ★ 646✓Active maintenance

Indexing history

1

What PulseGate has recorded for this listing

  1. Indexed31 Jul · 02:51 UTC
    OWASP/cve-lite-cli verified against its public source
    Source: PulseGate · Open ↗

Frequently asked questions about CVE Lite CLI

What does CVE Lite CLI do?
Finding, understanding, and fixing vulnerable dependencies in JS/TS lockfiles without relying on cloud services or CI pipelines. It is catalogued under CLI tools & terminal on PulseGate.
Who is CVE Lite CLI for?
CVE Lite CLI is an open-source project built for developers.
Does CVE Lite CLI have a free plan?
Yes — CVE Lite CLI is open source under the MIT license and free to use.
What platforms does CVE Lite CLI run on?
CVE Lite CLI runs on the command line. It can also be self-hosted.
Is CVE Lite CLI still maintained?
The GitHub repository shows 319 commits in the last 90 days.
What projects are similar to CVE Lite CLI?
Similar projects tracked by PulseGate include isaac-acp, applyr, and cosmo-cli.isaac-acpapplyrcosmo-cli
Who makes CVE Lite CLI?
CVE Lite CLI is developed by OWASP Foundation, based in the United States.
How long has CVE Lite CLI been around?
CVE Lite CLI first shipped in 2026.

At a glance

Platforms
Cli
Languages
English
Open source
Yes · ★ 646
License
MIT
First seen
31 Jul 2026
Built for
developers
Model
Open source
Solves
Finding, understanding, and fixing vulnerable dependencies in JS/TS lockfiles without relying on cloud services or CI pipelines.

Registered as

GitHub
OWASP/cve-lite-cli
GitHub
OWASP/DockSec
GitHub
OWASP/Nest

Developer

🇺🇸OWASP Foundation
Community-driven
↗ GitHub

Open source

View on GitHub →
Stars
646
Forks
116
Open issues
39
Last commit
30 Jul 2026
Commits 90d
319
Contributors
42
Authorship
Community-driven
Default branch
main
Latest release
v1.28.0 · 26 Jul 2026

Live coverage

Identity confidence
High · 88
Indexed
31 Jul 2026
Lifecycle
Alive
First seen
Jul 2026
Last seen
31 Jul 2026
Identity audit (13)
Slug
owasp-cve-lite-cli-owasp-org
Lifecycle state recorded
31 Jul 2026
Verification state
Indexed for public listing
Listing state
Listed: yes
Index status
Included in index
Latest evidence snapshot
31 Jul 2026
Timeline basis
Indexed-at chronology (no inferred launch/funding milestones).
Name from
Written by a language model from the project's public pages.
Category from
Assigned by a language model.
Summary from
Written by a language model from public pages.
Languages from
Detected by a language model from page content.
Last updated
4 Aug 2026
Canonical URL
https://owasp.org/cve-lite-cli

Ship this? Send a correction — no account, and you get a link to follow it.

Also in CLI tools & terminal

Same category — not a similarity match

  • ISisaac-acppypi.org
  • APapplyrpypi.org
  • COcosmo-clipypi.org
  • GIgit-standupgithub.com
  • CLclipassmanpypi.org
  • JEjetson-clipypi.org