Skip to content

Open Source Friday - CVE Lite CLI #250

Description

@sonukapoor

Name

Sonu Kapoor

GitHub Handle

@sonukapoor

Tell us about yourself

I'm a developer and open source maintainer focused on application security tooling. I created CVE Lite CLI, a dependency vulnerability scanner for JavaScript and TypeScript projects that's now an OWASP Lab Project. I've been building in public since March 2026 - the project hit 30K+ npm downloads in under four months and has been covered by The Register, SD Times, SecurityWeek, CSO Online, and Help Net Security.

Project Name

CVE Lite CLI

Project Repo Link

https://github.com/OWASP/cve-lite-cli

Stream Date

  • Yes
  • Not yet

Dates

No response

Twitter URL

@SonuKapoor1978

LinkedIn URL

https://www.linkedin.com/in/sonu-kapoor/

Additional Information

CVE Lite CLI is a fast, local dependency vulnerability scanner for npm, pnpm, Yarn, and Bun projects. It classifies every finding as direct or transitive, validates fix versions against OSV before recommending them, and gives developers the exact upgrade command to run - not just a list of advisory IDs. It runs entirely locally; no login or API key required.

It graduated as an OWASP Lab Project in June 2026 and has been adopted by teams across fintech, government, and developer tooling - including French government ministries and organizations in the US, Canada, Portugal, and Brazil. I'd love to walk through how it works, what makes it different from npm audit and Dependabot, and where the project is headed.

Metadata

Metadata

Labels

open-sourceAnything related to open sourceopen-source-fridayweekly Twitch stream with maintainerspendinginvited guests that are pending approval/schedulingtwitch

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions