{"_id":"@312npm/cve-monitor","name":"@312npm/cve-monitor","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@312npm/cve-monitor","version":"1.0.0","description":"Dependency security monitor — reports your project's dependencies to 312 Elements for nightly CVE scanning","license":"MIT","author":{"name":"312 Elements","email":"hello@312elements.com"},"homepage":"https://seo.312elements.com","repository":{"type":"git","url":"https://git.loveschacht.app/mschachtjr/keyword-tracker-saas"},"keywords":["cve","security","vulnerability","dependency","monitor","npm-audit"],"bin":{"cve-monitor":"bin/cve-monitor.cjs"},"scripts":{"postinstall":"node ./bin/setup.cjs"},"engines":{"node":">=16"},"_id":"@312npm/cve-monitor@1.0.0","gitHead":"a4cae53a4e8aa663a0872ebddd8c780ed2aa1780","_nodeVersion":"20.19.4","_npmVersion":"10.8.2","dist":{"integrity":"sha512-1GPCH6DGS4TT3iPMFbOhDsUBGgQFELuL/RGaffzY9QoiSsDHJbklz4aOj1PZaXYBs8dZf7DknUG4PrO+8EUzXw==","shasum":"64861490dc91ed162740ef88b25c5c916222cbd7","tarball":"https://registry.npmjs.org/@312npm/cve-monitor/-/cve-monitor-1.0.0.tgz","fileCount":5,"unpackedSize":12578,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIEJKjfAFcwI9f1hWXsPFaSmrOXhQPVJ4GVlzpMHx76mRAiBkk2px+JEjmIpAeS/VF1FaTXyLCuNcHm86GgEvvNmSuA=="}]},"_npmUser":{"name":"312elements","email":"michael@312elements.com"},"directories":{},"maintainers":[{"name":"312elements","email":"michael@312elements.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/cve-monitor_1.0.0_1772603674729_0.7643564001281751"},"_hasShrinkwrap":false}},"time":{"created":"2026-03-04T05:54:34.647Z","1.0.0":"2026-03-04T05:54:34.903Z","modified":"2026-03-04T05:54:35.129Z"},"maintainers":[{"name":"312elements","email":"michael@312elements.com"}],"description":"Dependency security monitor — reports your project's dependencies to 312 Elements for nightly CVE scanning","homepage":"https://seo.312elements.com","keywords":["cve","security","vulnerability","dependency","monitor","npm-audit"],"repository":{"type":"git","url":"https://git.loveschacht.app/mschachtjr/keyword-tracker-saas"},"author":{"name":"312 Elements","email":"hello@312elements.com"},"license":"MIT","readme":"# @312npm/cve-monitor\n\nDependency security monitor from [312 Elements](https://seo.312elements.com). Reports your project's dependencies on every build so we can scan them nightly for known CVEs and email you when action is needed.\n\n## What it does\n\n- Reads your lock file (package-lock.json, yarn.lock, or pnpm-lock.yaml)\n- Sends package names and versions to the 312 Elements API\n- **No source code, secrets, or environment variables are sent**\n- Always exits 0 — will never break your build\n\n## Install\n\n```bash\nnpm install --save-dev @312npm/cve-monitor\n```\n\nAdd to your build command in `package.json`:\n\n```json\n{\n  \"scripts\": {\n    \"build\": \"cve-monitor && next build\"\n  }\n}\n```\n\n## Domain detection\n\nYour site's domain is detected automatically (no config needed):\n\n1. `BEACON_DOMAIN` environment variable (explicit override)\n2. `VERCEL_PROJECT_PRODUCTION_URL` (Vercel sets this automatically)\n3. `homepage` field in package.json\n\n## How it works\n\nOn every build, the script sends your dependency list to 312 Elements. Each night, we scan all reported dependencies against the [OSV.dev](https://osv.dev) vulnerability database. If a CVE is found in one of your packages, you receive an email with what's affected and how to fix it.\n\nThis is a companion to `npm audit` — it provides ongoing, passive monitoring so you don't have to remember to check manually.\n\n## Requirements\n\n- Node.js >= 16\n- A 312 Elements account at [seo.312elements.com](https://seo.312elements.com)\n","readmeFilename":"README.md","_rev":"1-edb78e09308561e04c88a900af35aa4b"}