
cve-lite-cli v1.29.0
Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix, JSON output, and practical remediation guidance.
Most tools tell you what's wrong. CVE Lite CLI tells you what to run.
CVE Lite CLI
🏆 Officially recognized as an OWASP Lab Project
Vulnerability scanning that starts in your terminal and fits cleanly into CI.
Scan your lockfile, get copy-and-run fix commands, and ship clean code.
Scan. Understand. Fix.
| 🏆 | 🎯 | 🔒 |
| OWASP Lab Project Peer-reviewed by the org behind the OWASP Top 10 — the security standard followed by millions of developers |
Remediation-first Validated fix commands + parent-aware transitive guidance — not just CVE IDs |
Runs locally Nothing leaves your machine — not your code, not your dependency tree |
🏆 Featured on GitHub Open Source Friday · Ranked #5 in Help Net Security's 20 open-source security tools · OpenSSF Best Practices
Covered by The Register · CSO Online · SecurityWeek · SD Times · DevOps.com · ReversingLabs
Running in CI at
SolidJS,
the Government of British Columbia as a required merge gate,
French government digital services (DINUM), and
Valibot.
In production use in France, Canada, Germany, Thailand and China.
⚡ One command. No account, no API key, nothing leaves your machine.
npx cve-lite-cli .
→ Quick Start
Quick Start • Usage • Screenshots • HTML Report • Compare • Roadmap • Contributing • Join Slack
Package Managers
npm |
pnpm |
Yarn |
Bun |
Quick start
npm install -g cve-lite-cli
cve-lite /path/to/project
Or one-off with npx:
npx cve-lite-cli /path/to/project
No account. No configuration. No source code leaves your machine.
Usage
cve-lite /path/to/project # basic scan
cve-lite /path/to/project --verbose # full fix plan with dependency paths
cve-lite /path/to/project --fix # apply validated direct fixes and rescan
cve-lite /path/to/project --fail-on high # exit non-zero on high severity and above
cve-lite /path/to/project --json # JSON output
cve-lite /path/to/project --sarif # SARIF output for GitHub Code Scanning
cve-lite /path/to/project --sbom spdx # SPDX 2.3 SBOM (also: --sbom cyclonedx)
cve-lite /path/to/project --sarif --output reports # write output files into ./reports
cve-lite /path/to/project --report # interactive HTML dashboard
cve-lite /path/to/project --check-overrides # audit override hygiene alongside the CVE scan
cve-lite /path/to/project --check-maintenance # flag CVE-blocking version drag and npm-deprecated direct deps
cve-lite /path/to/project --check-licenses # detect copyleft and unknown licenses alongside the CVE scan
cve-lite advisories sync # sync advisory DB for offline use
cve-lite advisories init # create an empty advisory DB to populate yourself
cve-lite /path/to/project --offline # scan with no runtime API calls
For the full flag reference and exit codes see the CLI Reference guide and Fix mode guide.
Override hygiene (overrides)
overrides and resolutions are powerful, but they rot. CVE Lite CLI audits them across npm, pnpm, yarn, and bun, catching thirteen classes of problem: