
Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix, JSON output, and practical remediation guidance.
Most tools tell you what's wrong. CVE Lite CLI tells you what to run.
🏆 Officially recognized as an OWASP Lab Project
Vulnerability scanning that starts in your terminal and fits cleanly into CI.
Scan your lockfile, get copy-and-run fix commands, and ship clean code.
Scan. Understand. Fix.
| 🏆 | 🎯 | 🔒 |
| OWASP Lab Project Peer-reviewed by the org behind the OWASP Top 10 — the security standard followed by millions of developers |
Remediation-first Validated fix commands + parent-aware transitive guidance — not just CVE IDs |
Runs locally Nothing leaves your machine — not your code, not your dependency tree |
🏆 Featured on GitHub Open Source Friday · Ranked #5 in Help Net Security's 20 open-source security tools · OpenSSF Best Practices
Covered by The Register · CSO Online · SecurityWeek · SD Times · DevOps.com · ReversingLabs
Running in CI at
SolidJS,
the Government of British Columbia as a required merge gate,
French government digital services (DINUM), and
Valibot.
In production use in France, Canada, Germany, Thailand and China.
⚡ One command. No account, no API key, nothing leaves your machine.
npx cve-lite-cli .
→ Quick Start
Quick Start • Usage • Screenshots • HTML Report • Compare • Roadmap • Contributing • Join Slack
Package Managers
npm |
pnpm |
Yarn |
Bun |
npm install -g cve-lite-cli
cve-lite /path/to/project
Or one-off with npx:
npx cve-lite-cli /path/to/project
No account. No configuration. No source code leaves your machine.
Note: CVE Lite CLI includes
better-sqlite3, a native SQLite binding used for the local advisory database. During installation, npm may download a prebuilt binary or compile one from source. This can produce extra console output — it is expected and is not CVE Lite CLI itself running an install script. See Dependency footprint for details.
cve-lite /path/to/project # basic scan
cve-lite /path/to/project --verbose # full fix plan with dependency paths
cve-lite /path/to/project --fix # apply validated direct fixes and rescan
cve-lite /path/to/project --fail-on high # exit non-zero on high severity and above
cve-lite /path/to/project --json # JSON output
cve-lite /path/to/project --sarif # SARIF output for GitHub Code Scanning
cve-lite /path/to/project --sbom spdx # SPDX 2.3 SBOM (also: --sbom cyclonedx)
cve-lite /path/to/project --sarif --output reports # write output files into ./reports
cve-lite /path/to/project --report # interactive HTML dashboard
cve-lite /path/to/project --check-overrides # audit override hygiene alongside the CVE scan
cve-lite /path/to/project --check-maintenance # flag CVE-blocking version drag and npm-deprecated direct deps
cve-lite /path/to/project --check-licenses # detect copyleft and unknown licenses alongside the CVE scan
cve-lite advisories sync # sync advisory DB for offline use
cve-lite advisories init # create an empty advisory DB to populate yourself
cve-lite /path/to/project --offline # scan with no runtime API calls