zebbern/depfence

Detect dependency confusion attack vectors in Node.js projects

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
severityMinimum severity threshold (critical, high, medium, low, info)nohigh
onlineCheck package names against public npm registrynofalse
workspaceScan all workspace packages in monoreponofalse
scopesSpace-separated scopes to check (e.g., @company @internal)no""
ignoreSpace-separated packages to ignoreno""
fail-onFail if findings at this severity or above (critical, high, medium, low, none)nohigh
namedescription
findingsTotal number of findings
criticalNumber of critical findings
highNumber of high findings
result-jsonFull scan result as JSON