{"_id":"@arcane-spark/ubel-node","_rev":"29-3fade0db9a1d310d656dcf55f4827bb0","name":"@arcane-spark/ubel-node","dist-tags":{"latest":"0.18.1"},"versions":{"0.1.0":{"name":"@arcane-spark/ubel-node","version":"0.1.0","keywords":["security","supply-chain","vulnerability","audit","firewall","sbom","osv","nvd","npm","pnpm","bun","dependencies","policy","sca","cve","compliance","scanner","infection","malware","yarn","devsecops","cvss","lockfile","cyclonedx"],"author":{"name":"Ala Bouali","email":"contact@alabouali.com"},"license":"AGPL-3.0-only","_id":"@arcane-spark/ubel-node@0.1.0","maintainers":[{"name":"alabouali","email":"ala.bouali.1997@gmail.com"}],"homepage":"https://github.com/AlaBouali/ubel#readme","bugs":{"url":"https://github.com/AlaBouali/ubel/issues"},"bin":{"ubel-bun":"bin/bun.js","ubel-npm":"bin/npm.js","ubel-pnpm":"bin/pnpm.js","ubel-agent":"bin/agent.js","ubel-platform":"bin/platform.js"},"dist":{"shasum":"9feb258f79ac3c5e4c70168761039cf469550055","tarball":"https://registry.npmjs.org/@arcane-spark/ubel-node/-/ubel-node-0.1.0.tgz","fileCount":32,"integrity":"sha512-ShfgRIxGJcfyxJOD6vBAD7o2GTwefQfTFOxfrWVkBNkkWL5ilLQS02otJBmLw5vn60RtB6npeHSsEPdwjJ7ImA==","signatures":[{"sig":"MEYCIQCb6lz4awKF6Oen6Z2rcXga3qgjz7QHR/tRDphAhk/fdQIhAKNTeDXbiOkiyvQhoeqlJFfzTkfknV5zTQeyrSyMrKgE","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":459697},"main":"src/main.js","type":"module","engines":{"node":">=18.0.0"},"exports":{".":"./src/main.js"},"gitHead":"c41d96af5803d405e73f3d8929ed60b980eb6e03","scripts":{"test":"node src/main.js npm health"},"_npmUser":{"name":"alabouali","email":"ala.bouali.1997@gmail.com"},"repository":{"url":"git+https://github.com/AlaBouali/ubel.git","type":"git","directory":"node"},"_npmVersion":"10.8.0","description":"Supply-chain security firewall for Node.js — resolves dependencies, scans via OSV.dev and NVD, and enforces configurable vulnerability policies before anything reaches node_modules.","directories":{},"_nodeVersion":"22.16.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ubel-node_0.1.0_1777934471187_0.35371160510746114","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@arcane-spark/ubel-node","version":"0.1.1","keywords":["security","supply-chain","vulnerability","audit","firewall","sbom","osv","nvd","npm","pnpm","bun","dependencies","policy","sca","cve","compliance","scanner","infection","malware","yarn","devsecops","cvss","lockfile","cyclonedx"],"author":{"name":"Ala Bouali","email":"contact@alabouali.com"},"license":"AGPL-3.0-only","_id":"@arcane-spark/ubel-node@0.1.1","maintainers":[{"name":"alabouali","email":"ala.bouali.1997@gmail.com"}],"homepage":"https://github.com/AlaBouali/ubel#readme","bugs":{"url":"https://github.com/AlaBouali/ubel/issues"},"bin":{"ubel-bun":"bin/bun.js","ubel-npm":"bin/npm.js","ubel-pnpm":"bin/pnpm.js","ubel-agent":"bin/agent.js","ubel-platform":"bin/platform.js"},"dist":{"shasum":"2a383163a2a9711a0c324312fa6bc05fd2078278","tarball":"https://registry.npmjs.org/@arcane-spark/ubel-node/-/ubel-node-0.1.1.tgz","fileCount":32,"integrity":"sha512-rlxO+mbz5h5KiAZ4TabsaFB8HZWdeldCrf5wQrUYckvfRKoVQQiLhwWWNJmKKtZLUgfP3HInor65XRbseVWqtQ==","signatures":[{"sig":"MEYCIQD+Fpb/clGi3PmuGLEA5dp0hlQHW+b1MRTDJT6RquuM9QIhAL4Z5EIKg14GSWrAIcfuMglDlfQSyy71vQ+IClJjeTXG","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":459729},"main":"src/main.js","type":"module","engines":{"node":">=18.0.0"},"exports":{".":"./src/main.js"},"gitHead":"050f841ad9fe3f2c20d78ea730684c2c546753c6","scripts":{"test":"node src/main.js npm health"},"_npmUser":{"name":"alabouali","email":"ala.bouali.1997@gmail.com"},"repository":{"url":"git+https://github.com/AlaBouali/ubel.git","type":"git","directory":"node"},"_npmVersion":"10.8.0","description":"Supply-chain security firewall for Node.js — resolves dependencies, scans via OSV.dev and NVD, and enforces configurable vulnerability policies before anything reaches node_modules.","directories":{},"_nodeVersion":"22.16.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ubel-node_0.1.1_1777943961195_0.8348790950859857","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@arcane-spark/ubel-node","version":"0.1.2","keywords":["security","supply-chain","vulnerability","audit","firewall","sbom","osv","nvd","npm","pnpm","bun","dependencies","policy","sca","cve","compliance","scanner","infection","malware","yarn","devsecops","cvss","lockfile","cyclonedx"],"author":{"name":"Ala Bouali","email":"contact@alabouali.com"},"license":"AGPL-3.0-only","_id":"@arcane-spark/ubel-node@0.1.2","maintainers":[{"name":"alabouali","email":"ala.bouali.1997@gmail.com"}],"homepage":"https://github.com/AlaBouali/ubel#readme","bugs":{"url":"https://github.com/AlaBouali/ubel/issues"},"bin":{"ubel-bun":"bin/bun.js","ubel-npm":"bin/npm.js","ubel-pnpm":"bin/pnpm.js","ubel-agent":"bin/agent.js","ubel-platform":"bin/platform.js"},"dist":{"shasum":"25407d1996d0fdcfa8f4293b276377f40f371bfb","tarball":"https://registry.npmjs.org/@arcane-spark/ubel-node/-/ubel-node-0.1.2.tgz","fileCount":32,"integrity":"sha512-Si2uBVc9Uj5jkSqkr1x9OUE1VJ4oBvibSqcpKoNCHANR9RVw9gWqgJsaJSUUENDz13qlVLS34g/OkB+GUDrB6Q==","signatures":[{"sig":"MEQCIDonvIoX/j9Vcna27XFvvlfEMZrEy+4JO/77bvY2bfx/AiAgrrSqVAedMXpQbun9/fUyNfMakhmKv0irLhdAdRt2IQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":459749},"main":"src/main.js","type":"module","engines":{"node":">=18.0.0"},"exports":{".":"./src/main.js"},"gitHead":"829199b09a8c0aeecfef4b7fe3d5ae642830d16d","scripts":{"test":"node src/main.js npm health"},"_npmUser":{"name":"alabouali","email":"ala.bouali.1997@gmail.com"},"repository":{"url":"git+https://github.com/AlaBouali/ubel.git","type":"git","directory":"node"},"_npmVersion":"10.8.0","description":"Supply-chain security firewall for Node.js — resolves dependencies, scans via OSV.dev and NVD, and enforces configurable vulnerability policies before anything reaches node_modules.","directories":{},"_nodeVersion":"22.16.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ubel-node_0.1.2_1778101696171_0.7434260469236766","host":"s3://npm-registry-packages-npm-production"}},"0.1.3":{"name":"@arcane-spark/ubel-node","version":"0.1.3","keywords":["security","supply-chain","vulnerability","audit","firewall","sbom","osv","nvd","npm","pnpm","bun","dependencies","policy","sca","cve","compliance","scanner","infection","malware","yarn","devsecops","cvss","lockfile","cyclonedx"],"author":{"name":"Ala Bouali","email":"contact@alabouali.com"},"license":"AGPL-3.0-only","_id":"@arcane-spark/ubel-node@0.1.3","maintainers":[{"name":"alabouali","email":"ala.bouali.1997@gmail.com"}],"homepage":"https://github.com/AlaBouali/ubel#readme","bugs":{"url":"https://github.com/AlaBouali/ubel/issues"},"bin":{"ubel-bun":"bin/bun.js","ubel-npm":"bin/npm.js","ubel-pnpm":"bin/pnpm.js","ubel-agent":"bin/agent.js","ubel-platform":"bin/platform.js"},"dist":{"shasum":"f0ee51e2350d4db78a539676109155d7042a90c9","tarball":"https://registry.npmjs.org/@arcane-spark/ubel-node/-/ubel-node-0.1.3.tgz","fileCount":32,"integrity":"sha512-nLwX0IE3LDZZ+Fy/Thg64sP2WWujqh1CqE3VSMd8HQo5JK2ahi7BsYnKlKik6VtXoBh/6J58P8RkP6PtsfyXIQ==","signatures":[{"sig":"MEUCIDYZ38qn/n6mdUCXleoGzf9yv2SSfYC1FKbgC5/jQG5PAiEAydm/CQIUhZV5RGhOmsYRo7oDfSoqwLmVVSAeUOhuGdM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":462529},"main":"src/main.js","type":"module","engines":{"node":">=18.0.0"},"exports":{".":"./src/main.js"},"gitHead":"f8bbc82d2b780bfd3a9577f1103bffe59168a6c5","scripts":{"test":"node src/main.js npm health"},"_npmUser":{"name":"alabouali","email":"ala.bouali.1997@gmail.com"},"repository":{"url":"git+https://github.com/AlaBouali/ubel.git","type":"git","directory":"node"},"_npmVersion":"10.8.0","description":"Supply-chain security firewall for Node.js — resolves dependencies, scans via OSV.dev and NVD, and enforces configurable vulnerability policies before anything reaches node_modules.","directories":{},"_nodeVersion":"22.16.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ubel-node_0.1.3_1778119093375_0.3836874563815782","host":"s3://npm-registry-packages-npm-production"}},"0.1.4":{"name":"@arcane-spark/ubel-node","version":"0.1.4","keywords":["security","supply-chain","vulnerability","audit","firewall","sbom","osv","nvd","npm","pnpm","bun","dependencies","policy","sca","cve","compliance","scanner","infection","malware","yarn","devsecops","cvss","lockfile","cyclonedx"],"author":{"name":"Ala Bouali","email":"contact@alabouali.com"},"license":"AGPL-3.0-only","_id":"@arcane-spark/ubel-node@0.1.4","maintainers":[{"name":"alabouali","email":"ala.bouali.1997@gmail.com"}],"homepage":"https://github.com/AlaBouali/ubel#readme","bugs":{"url":"https://github.com/AlaBouali/ubel/issues"},"bin":{"ubel-bun":"bin/bun.js","ubel-npm":"bin/npm.js","ubel-pnpm":"bin/pnpm.js","ubel-agent":"bin/agent.js","ubel-platform":"bin/platform.js"},"dist":{"shasum":"d13302a7ac3a0d40330d2114f1f293b264149d77","tarball":"https://registry.npmjs.org/@arcane-spark/ubel-node/-/ubel-node-0.1.4.tgz","fileCount":32,"integrity":"sha512-GGN721z0cDBo5m013N+WXw3DMDNih/fVG8vUlXmKSBd1pd2OIvLlAPJSunAaU2lAfbNseDvgTstDQZIEGiMrkQ==","signatures":[{"sig":"MEQCIB7FIrgD2bJdxfTvX8uxn0X2JtWRBQT/XVCzLEgG2L0nAiApx+LDsQjxgLt1qOcpz0rvANd18yJtT7d0Lc9L3kAwqg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":462094},"main":"src/main.js","type":"module","engines":{"node":">=18.0.0"},"exports":{".":"./src/main.js"},"gitHead":"83ae18368b6b63f4a48d94071d0b6df2126871b8","scripts":{"test":"node src/main.js npm health"},"_npmUser":{"name":"alabouali","email":"ala.bouali.1997@gmail.com"},"repository":{"url":"git+https://github.com/AlaBouali/ubel.git","type":"git","directory":"node"},"_npmVersion":"10.8.0","description":"Supply-chain security firewall for Node.js — resolves dependencies, scans via OSV.dev and NVD, and enforces configurable vulnerability policies before anything reaches node_modules.","directories":{},"_nodeVersion":"22.16.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ubel-node_0.1.4_1778176296971_0.7280664217265429","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@arcane-spark/ubel-node","version":"0.2.0","keywords":["security","supply-chain","vulnerability","audit","firewall","sbom","osv","nvd","npm","pnpm","bun","dependencies","policy","sca","cve","compliance","scanner","infection","malware","yarn","devsecops","cvss","lockfile","cyclonedx"],"author":{"name":"Ala Bouali","email":"contact@alabouali.com"},"license":"AGPL-3.0-only","_id":"@arcane-spark/ubel-node@0.2.0","maintainers":[{"name":"alabouali","email":"ala.bouali.1997@gmail.com"}],"homepage":"https://github.com/AlaBouali/ubel#readme","bugs":{"url":"https://github.com/AlaBouali/ubel/issues"},"bin":{"ubel-bun":"bin/bun.js","ubel-npm":"bin/npm.js","ubel-pnpm":"bin/pnpm.js","ubel-agent":"bin/agent.js","ubel-platform":"bin/platform.js"},"dist":{"shasum":"6fa027f60e7f737e73927f520f097564e286c5b7","tarball":"https://registry.npmjs.org/@arcane-spark/ubel-node/-/ubel-node-0.2.0.tgz","fileCount":33,"integrity":"sha512-UHLu2epywvCOwMne8dfySAYaSnFTqdd46aN5dLihk59h39301i9vnOh07gBJe0oIc+k2XnZmGwDACuXMbrBW2A==","signatures":[{"sig":"MEQCIA5Ku8NhGl2/rcqoDjZcBr1bPHUIPV2wieAXA6dhD8a+AiAlZh67DB6puQ6vJUGV4gOY03CRTwEZAkdLO21LAY2MaQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":484425},"main":"src/main.js","type":"module","engines":{"node":">=18.0.0"},"exports":{".":"./src/main.js"},"gitHead":"485f2897c7a93ca80d3a38a1ff06cc9826ef1ee8","scripts":{"test":"node src/main.js npm health"},"_npmUser":{"name":"alabouali","email":"ala.bouali.1997@gmail.com"},"repository":{"url":"git+https://github.com/AlaBouali/ubel.git","type":"git","directory":"node"},"_npmVersion":"10.8.0","description":"Supply-chain security firewall for Node.js — resolves dependencies, scans via OSV.dev and NVD, and enforces configurable vulnerability policies before anything reaches node_modules.","directories":{},"_nodeVersion":"22.16.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ubel-node_0.2.0_1778458389457_0.3095277536796255","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@arcane-spark/ubel-node","version":"0.3.0","keywords":["security","supply-chain","vulnerability","audit","firewall","sbom","osv","nvd","npm","pnpm","bun","dependencies","policy","sca","cve","compliance","scanner","infection","malware","yarn","devsecops","cvss","lockfile","cyclonedx"],"author":{"name":"Ala Bouali","email":"contact@alabouali.com"},"license":"SEE LICENSE IN LICENSE.md","_id":"@arcane-spark/ubel-node@0.3.0","maintainers":[{"name":"alabouali","email":"ala.bouali.1997@gmail.com"}],"homepage":"https://github.com/AlaBouali/ubel#readme","bugs":{"url":"https://github.com/AlaBouali/ubel/issues"},"bin":{"ubel-bun":"bin/bun.js","ubel-npm":"bin/npm.js","ubel-pnpm":"bin/pnpm.js","ubel-agent":"bin/agent.js","ubel-platform":"bin/platform.js"},"dist":{"shasum":"9ceb742f55f703609e8c7faa3be54eb82e445849","tarball":"https://registry.npmjs.org/@arcane-spark/ubel-node/-/ubel-node-0.3.0.tgz","fileCount":34,"integrity":"sha512-uWh3skO4/7IWjAw3KCil/gwVNi4ujFd0fAzGtNLoGHQnKiDgGz0rtK7bIep4dAwSt27T60An2dre+gVXs1rXsg==","signatures":[{"sig":"MEQCICAlO9tPGDrGfmWmdLSyOm0ZLB/p6Ni2PabuSV1ERvbwAiA1/7qqV7rwAldfHpG5x6X2rlepu48D7J+XpSJQhOhYkQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":477813},"main":"src/main.js","type":"module","engines":{"node":">=18.0.0"},"exports":{".":"./src/main.js"},"gitHead":"63cd2eafb883fa47c3e34a8bea146c274ad5e4cb","scripts":{"test":"node src/main.js npm health"},"_npmUser":{"name":"alabouali","email":"ala.bouali.1997@gmail.com"},"repository":{"url":"git+https://github.com/AlaBouali/ubel.git","type":"git","directory":"node"},"_npmVersion":"10.8.0","description":"Supply-chain security firewall for Node.js — resolves dependencies, scans via OSV.dev and NVD, and enforces configurable vulnerability policies before anything reaches node_modules.","directories":{},"_nodeVersion":"22.16.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ubel-node_0.3.0_1779336555648_0.7453150863420162","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@arcane-spark/ubel-node","version":"0.4.0","keywords":["security","supply-chain","vulnerability","audit","firewall","sbom","osv","nvd","npm","pnpm","bun","dependencies","policy","sca","cve","compliance","scanner","infection","malware","yarn","devsecops","cvss","lockfile","cyclonedx"],"author":{"name":"Ala Bouali","email":"contact@alabouali.com"},"license":"SEE LICENSE IN LICENSE.md","_id":"@arcane-spark/ubel-node@0.4.0","maintainers":[{"name":"alabouali","email":"ala.bouali.1997@gmail.com"}],"homepage":"https://github.com/AlaBouali/ubel#readme","bugs":{"url":"https://github.com/AlaBouali/ubel/issues"},"bin":{"ubel-bun":"bin/bun.js","ubel-npm":"bin/npm.js","ubel-pnpm":"bin/pnpm.js","ubel-agent":"bin/agent.js","ubel-platform":"bin/platform.js"},"dist":{"shasum":"e024d5bce38e0c16f781a8a54511ac0b79c7703c","tarball":"https://registry.npmjs.org/@arcane-spark/ubel-node/-/ubel-node-0.4.0.tgz","fileCount":36,"integrity":"sha512-kc1GCGV+xNdSW0lwKhraVXFLSuo7UI+DzXE+iDVcqnpidC97C58ozz28T/q5vllK5rXRyy4PzTECcCeyACdBrQ==","signatures":[{"sig":"MEUCIQC+QFndu1LPZtL9X5F/pOuD4411QdB/Wa/vhwx8mPzxhQIgdbxl8JfwSN9AdnNE6Gb0s1SbTi2/c1ZC/Pipfv3OQDc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":566983},"main":"src/main.js","type":"module","engines":{"node":">=18.0.0"},"exports":{".":"./src/main.js"},"gitHead":"2112644c079eec7398e107c220d96968bf4fca6f","scripts":{"test":"node src/main.js npm health"},"_npmUser":{"name":"alabouali","email":"ala.bouali.1997@gmail.com"},"repository":{"url":"git+https://github.com/AlaBouali/ubel.git","type":"git","directory":"node"},"_npmVersion":"10.8.0","description":"Supply-chain security firewall for Node.js — resolves dependencies, scans via OSV.dev and NVD, and enforces configurable vulnerability policies before anything reaches node_modules.","directories":{},"_nodeVersion":"22.16.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ubel-node_0.4.0_1782583306820_0.5252516287550919","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@arcane-spark/ubel-node","version":"0.5.0","keywords":["security","supply-chain","vulnerability","audit","firewall","sbom","osv","nvd","npm","pnpm","bun","dependencies","policy","sca","cve","compliance","scanner","infection","malware","yarn","devsecops","cvss","lockfile","cyclonedx"],"author":{"name":"Ala Bouali","email":"contact@alabouali.com"},"license":"SEE LICENSE IN LICENSE.md","_id":"@arcane-spark/ubel-node@0.5.0","maintainers":[{"name":"alabouali","email":"ala.bouali.1997@gmail.com"}],"homepage":"https://github.com/AlaBouali/ubel#readme","bugs":{"url":"https://github.com/AlaBouali/ubel/issues"},"bin":{"ubel-bun":"bin/bun.js","ubel-npm":"bin/npm.js","ubel-pnpm":"bin/pnpm.js","ubel-agent":"bin/agent.js","ubel-platform":"bin/platform.js"},"dist":{"shasum":"7b56509bf64dacc4b2a82d162bc41d93516c9436","tarball":"https://registry.npmjs.org/@arcane-spark/ubel-node/-/ubel-node-0.5.0.tgz","fileCount":36,"integrity":"sha512-vQ3kTumVvxUCo/9bqh5h+PXxuNn1sq4fUk42ibG35FWmEv+He7Ebh3exY7D7I4469OZW7+ezIJU3me19dQwyPg==","signatures":[{"sig":"MEYCIQC2foYFuYFao9aFNGMHSiYCXU+DyI/IF0GGzxviIbupRAIhAPSa2k5+6vbtvPnh6qsz+eNYn4b67C6zRqg3N1EcfwZL","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":566983},"main":"src/main.js","type":"module","engines":{"node":">=18.0.0"},"exports":{".":"./src/main.js"},"gitHead":"2112644c079eec7398e107c220d96968bf4fca6f","scripts":{"test":"node src/main.js npm health"},"_npmUser":{"name":"alabouali","email":"ala.bouali.1997@gmail.com"},"repository":{"url":"git+https://github.com/AlaBouali/ubel.git","type":"git","directory":"node"},"_npmVersion":"10.8.0","description":"Supply-chain security firewall for Node.js — resolves dependencies, scans via OSV.dev and NVD, and enforces configurable vulnerability policies before anything reaches node_modules.","directories":{},"_nodeVersion":"22.16.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ubel-node_0.5.0_1782583372609_0.6051313468683748","host":"s3://npm-registry-packages-npm-production"}},"0.6.0":{"name":"@arcane-spark/ubel-node","version":"0.6.0","keywords":["security","supply-chain","vulnerability","audit","firewall","sbom","osv","nvd","npm","pnpm","bun","dependencies","policy","sca","cve","compliance","scanner","infection","malware","yarn","devsecops","cvss","lockfile","cyclonedx"],"author":{"name":"Ala Bouali","email":"contact@alabouali.com"},"license":"SEE LICENSE IN LICENSE.md","_id":"@arcane-spark/ubel-node@0.6.0","maintainers":[{"name":"alabouali","email":"ala.bouali.1997@gmail.com"}],"homepage":"https://github.com/AlaBouali/ubel#readme","bugs":{"url":"https://github.com/AlaBouali/ubel/issues"},"bin":{"ubel-bun":"bin/bun.js","ubel-npm":"bin/npm.js","ubel-pnpm":"bin/pnpm.js","ubel-agent":"bin/agent.js","ubel-platform":"bin/platform.js"},"dist":{"shasum":"646c492b12da39ddaa6d3d1d0d11cbbe86b7403f","tarball":"https://registry.npmjs.org/@arcane-spark/ubel-node/-/ubel-node-0.6.0.tgz","fileCount":36,"integrity":"sha512-scxmpUvLdAT3VuK3SxVGcYU2Ug9KyZVAONCNPyJ+jB7LcPv/06knB8nJ0j71Ryx9ZkCtHyLdckqUoz1P1nYIaA==","signatures":[{"sig":"MEYCIQD+e7+chr0KN1fued+YUoEIQ5+hvoTWhYUNbxUjLQ1NSwIhAK57BpfWOEDK6XU7UJE8UYA0LSemvsETi1Xb1bP0FNWr","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":566995},"main":"src/main.js","type":"module","engines":{"node":">=18.0.0"},"exports":{".":"./src/main.js"},"gitHead":"8ae195daa8bfb5cb0d852b38da7f0b333fd405e6","scripts":{"test":"node src/main.js npm health"},"_npmUser":{"name":"alabouali","email":"ala.bouali.1997@gmail.com"},"repository":{"url":"git+https://github.com/AlaBouali/ubel.git","type":"git","directory":"node"},"_npmVersion":"10.8.0","description":"Supply-chain security firewall for Node.js — resolves dependencies, scans via OSV.dev and NVD, and enforces configurable vulnerability policies before anything reaches node_modules.","directories":{},"_nodeVersion":"22.16.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ubel-node_0.6.0_1782585123715_0.05775414526613876","host":"s3://npm-registry-packages-npm-production"}},"0.7.0":{"name":"@arcane-spark/ubel-node","version":"0.7.0","keywords":["security","supply-chain","vulnerability","audit","firewall","sbom","osv","nvd","npm","pnpm","bun","dependencies","policy","sca","cve","compliance","scanner","infection","malware","yarn","devsecops","cvss","lockfile","cyclonedx"],"author":{"name":"Ala Bouali","email":"ala.bouali.1997@gmail.com"},"license":"SEE LICENSE IN LICENSE.md","_id":"@arcane-spark/ubel-node@0.7.0","maintainers":[{"name":"alabouali","email":"ala.bouali.1997@gmail.com"}],"homepage":"https://github.com/AlaBouali/ubel#readme","bugs":{"url":"https://github.com/AlaBouali/ubel/issues"},"bin":{"ubel-bun":"bin/bun.js","ubel-mal":"bin/mal.js","ubel-npm":"bin/npm.js","ubel-pnpm":"bin/pnpm.js","ubel-sast":"bin/sast.js","ubel-agent":"bin/agent.js","ubel-chunk":"bin/chunk.js","ubel-platform":"bin/platform.js"},"dist":{"shasum":"f65e688a16c3ca75b8a4cf824c5bee4627e9ea12","tarball":"https://registry.npmjs.org/@arcane-spark/ubel-node/-/ubel-node-0.7.0.tgz","fileCount":79,"integrity":"sha512-J0yUhMKkCVU2m1qM7uifga7rOV4RX06KeFq7p3Q2xi6VDkCq+dyA2+LKrjF6suUDw7R5/7+y+X28RQjcxu4WUQ==","signatures":[{"sig":"MEUCIQCLqRd4T2r5zt/m0SapwNN9VeeB2862EFGNgcQb/0Q8pAIgfEa2C6JXvh5f6XOcEzAt0R+xx/Y5VI+mOVbn1NpP3Mo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":961116},"main":"sca/main.js","type":"module","engines":{"node":">=18.0.0"},"exports":{"./sca":"./sca/main.js","./sast":"./sast/main.js"},"gitHead":"baa283aed746ef68f7d2c2dddb8d1ac24b6395c3","scripts":{},"_npmUser":{"name":"alabouali","email":"ala.bouali.1997@gmail.com"},"repository":{"url":"git+https://github.com/AlaBouali/ubel.git","type":"git","directory":"node"},"_npmVersion":"10.8.0","description":"Software supply-chain and source-code security for Node.js. SCA: resolves dependencies, scans via OSV.dev and NVD, and annotates findings with heuristic reachability (SBOM/CycloneDX + SARIF reporting). Firewall: gates npm/pnpm/bun installs behind a lockfi","directories":{},"_nodeVersion":"22.16.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ubel-node_0.7.0_1784887861390_0.7477481389741454","host":"s3://npm-registry-packages-npm-production"}},"0.8.0":{"name":"@arcane-spark/ubel-node","version":"0.8.0","keywords":["security","supply-chain","vulnerability","audit","firewall","sbom","osv","nvd","npm","pnpm","bun","dependencies","policy","sca","cve","compliance","scanner","infection","malware","yarn","devsecops","cvss","lockfile","cyclonedx"],"author":{"name":"Ala Bouali","email":"ala.bouali.1997@gmail.com"},"license":"SEE LICENSE IN LICENSE.md","_id":"@arcane-spark/ubel-node@0.8.0","maintainers":[{"name":"alabouali","email":"ala.bouali.1997@gmail.com"}],"homepage":"https://github.com/AlaBouali/ubel#readme","bugs":{"url":"https://github.com/AlaBouali/ubel/issues"},"bin":{"ubel-bun":"bin/bun.js","ubel-mal":"bin/mal.js","ubel-npm":"bin/npm.js","ubel-cicd":"bin/cicd.js","ubel-pnpm":"bin/pnpm.js","ubel-sast":"bin/sast.js","ubel-yarn":"bin/yarn.js","ubel-agent":"bin/agent.js","ubel-chunk":"bin/chunk.js","ubel-docker":"bin/docker.js","ubel-license":"bin/license.js","ubel-secrets":"bin/secrets.js","ubel-platform":"bin/platform.js"},"dist":{"shasum":"ef77abe4c7dd1ca41df046fa06baf8710a6c9f48","tarball":"https://registry.npmjs.org/@arcane-spark/ubel-node/-/ubel-node-0.8.0.tgz","fileCount":93,"integrity":"sha512-w9KcL1S16YvMXVJWbnF7XRDAvJKq6pVCE/VAM6nRdRNO3DDDnH40MwyDD836nERi1b2PqoexKQdP96Svq4trUw==","signatures":[{"sig":"MEYCIQDtiq5ftQk0/29bBQOyrOU2jlMihICXc7p0tEJ7K06f0wIhAOwcUrdSgx4cRcJuNoKTkcxsv65+eJJXSU4b2w7Zp8Bf","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1208454},"main":"sca/main.js","type":"module","engines":{"node":">=18.0.0"},"exports":{"./sca":"./sca/main.js","./sast":"./sast/main.js"},"gitHead":"4d7d076dd5828f571067af7ceae80b8d75bfe1dd","scripts":{},"_npmUser":{"name":"alabouali","email":"ala.bouali.1997@gmail.com"},"repository":{"url":"git+https://github.com/AlaBouali/ubel.git","type":"git","directory":"node"},"_npmVersion":"10.8.0","description":"Software supply-chain and source-code security for Node.js. SCA: resolves dependencies, scans via OSV.dev and NVD, and annotates findings with heuristic reachability (SBOM/CycloneDX + SARIF reporting). Firewall: gates npm/pnpm/bun installs behind a lockfi","directories":{},"_nodeVersion":"22.16.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ubel-node_0.8.0_1785597309079_0.16027786488081786","host":"s3://npm-registry-packages-npm-production"}},"0.8.1":{"name":"@arcane-spark/ubel-node","version":"0.8.1","keywords":["security","supply-chain","vulnerability","audit","firewall","sbom","osv","nvd","npm","pnpm","bun","dependencies","policy","sca","cve","compliance","scanner","infection","malware","yarn","devsecops","cvss","lockfile","cyclonedx"],"author":{"name":"Ala Bouali","email":"ala.bouali.1997@gmail.com"},"license":"SEE LICENSE IN LICENSE.md","_id":"@arcane-spark/ubel-node@0.8.1","maintainers":[{"name":"alabouali","email":"ala.bouali.1997@gmail.com"}],"homepage":"https://github.com/AlaBouali/ubel#readme","bugs":{"url":"https://github.com/AlaBouali/ubel/issues"},"bin":{"ubel-bun":"bin/bun.js","ubel-mal":"bin/mal.js","ubel-npm":"bin/npm.js","ubel-cicd":"bin/cicd.js","ubel-pnpm":"bin/pnpm.js","ubel-sast":"bin/sast.js","ubel-yarn":"bin/yarn.js","ubel-agent":"bin/agent.js","ubel-chunk":"bin/chunk.js","ubel-docker":"bin/docker.js","ubel-license":"bin/license.js","ubel-secrets":"bin/secrets.js","ubel-platform":"bin/platform.js"},"dist":{"shasum":"b623450ae816ec35faaf84be1e6f76c317f01e75","tarball":"https://registry.npmjs.org/@arcane-spark/ubel-node/-/ubel-node-0.8.1.tgz","fileCount":93,"integrity":"sha512-NIn+CDsiRjPbXzfzoHO0QOU7RY6mcDWYAy5DM54paCe0yEtKbXdNhsRB87IVx8kOTnHVH02wCyGtqEH2bsTlng==","signatures":[{"sig":"MEUCIG0zwOWeUO/2wSbi37QD3oiV53KEdMxlZUMadl3qp0g0AiEAkD3/UrehXhdTwLtPfwKqXwJLOkHpXsgm0a7kpfwMqQg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1208457},"main":"sca/main.js","type":"module","engines":{"node":">=18.0.0"},"exports":{"./sca":"./sca/main.js","./sast":"./sast/main.js"},"gitHead":"77b78b47842983226572de7eac300bbf1a2ccc09","scripts":{},"_npmUser":{"name":"alabouali","email":"ala.bouali.1997@gmail.com"},"repository":{"url":"git+https://github.com/AlaBouali/ubel.git","type":"git","directory":"node"},"_npmVersion":"10.8.0","description":"Software supply-chain and source-code security for Node.js. SCA: resolves dependencies, scans via OSV.dev and NVD, and annotates findings with heuristic reachability (SBOM/CycloneDX + SARIF reporting). Firewall: gates npm/pnpm/bun installs behind a lockfi","directories":{},"_nodeVersion":"22.16.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ubel-node_0.8.1_1785615506432_0.18901234275062562","host":"s3://npm-registry-packages-npm-production"}},"0.9.0":{"name":"@arcane-spark/ubel-node","version":"0.9.0","keywords":["security","supply-chain","vulnerability","audit","firewall","sbom","osv","nvd","npm","pnpm","bun","dependencies","policy","sca","cve","compliance","scanner","infection","malware","yarn","devsecops","cvss","lockfile","cyclonedx","sast","secrets","secret scanning","credential detection","grc","devops","devsecops","sarif","license","license compliance","backdoor","supply chain","software composition analysis","software supply chain","information security","application security","application security testing","appsec","iac","infrastructure as code","docker","container security"],"author":{"name":"Ala Bouali","email":"ala.bouali.1997@gmail.com"},"license":"SEE LICENSE IN LICENSE.md","_id":"@arcane-spark/ubel-node@0.9.0","maintainers":[{"name":"alabouali","email":"ala.bouali.1997@gmail.com"}],"homepage":"https://github.com/AlaBouali/ubel#readme","bugs":{"url":"https://github.com/AlaBouali/ubel/issues"},"bin":{"ubel-bun":"bin/bun.js","ubel-mal":"bin/mal.js","ubel-npm":"bin/npm.js","ubel-cicd":"bin/cicd.js","ubel-pnpm":"bin/pnpm.js","ubel-sast":"bin/sast.js","ubel-yarn":"bin/yarn.js","ubel-agent":"bin/agent.js","ubel-chunk":"bin/chunk.js","ubel-docker":"bin/docker.js","ubel-license":"bin/license.js","ubel-secrets":"bin/secrets.js","ubel-platform":"bin/platform.js"},"dist":{"shasum":"b2235a28df5a7879d01f490a4cb20e5d67c568bc","tarball":"https://registry.npmjs.org/@arcane-spark/ubel-node/-/ubel-node-0.9.0.tgz","fileCount":93,"integrity":"sha512-wyJJK+wo78j0rYexpWCtjnL3zp52gqeiuho7YhbZe88IAJYSDq293ayYxtSivhLZqIE+pb9RDpPLpO+546JwRg==","signatures":[{"sig":"MEUCIQDkzDefIg9JDUweLpNB2D+zktp5aWJQH2YXQX5vofsuZAIgcv9jEoSc62gO6uYJxrg94gzLpvc2V/RGOX0ON8LvYtI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1229455},"main":"sca/main.js","type":"module","engines":{"node":">=18.0.0"},"exports":{"./sca":"./sca/main.js","./sast":"./sast/main.js"},"gitHead":"1ec5dd99368ca89b505bd93bf31dbee8fb55c86e","scripts":{},"_npmUser":{"name":"alabouali","email":"ala.bouali.1997@gmail.com"},"repository":{"url":"git+https://github.com/AlaBouali/ubel.git","type":"git","directory":"node"},"_npmVersion":"10.8.0","description":"Software supply-chain and source-code security for Node.js. SCA: resolves dependencies, scans via OSV.dev and NVD, and annotates findings with heuristic reachability (SBOM/CycloneDX + SARIF reporting). Firewall: gates npm/pnpm/bun installs behind a lockfi","directories":{},"_nodeVersion":"22.16.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ubel-node_0.9.0_1785616888277_0.3684985990289018","host":"s3://npm-registry-packages-npm-production"}},"0.10.0":{"name":"@arcane-spark/ubel-node","version":"0.10.0","keywords":["security","supply-chain","vulnerability","audit","firewall","sbom","osv","nvd","npm","pnpm","bun","dependencies","policy","sca","cve","compliance","scanner","infection","malware","yarn","devsecops","cvss","lockfile","cyclonedx","sast","secrets","secret scanning","credential detection","grc","devops","devsecops","sarif","license","license compliance","backdoor","supply chain","software composition analysis","software supply chain","information security","application security","application security testing","appsec","iac","infrastructure as code","docker","container security"],"author":{"name":"Ala Bouali","email":"ala.bouali.1997@gmail.com"},"license":"SEE LICENSE IN LICENSE.md","_id":"@arcane-spark/ubel-node@0.10.0","maintainers":[{"name":"alabouali","email":"ala.bouali.1997@gmail.com"}],"homepage":"https://github.com/AlaBouali/ubel#readme","bugs":{"url":"https://github.com/AlaBouali/ubel/issues"},"bin":{"ubel-bun":"bin/bun.js","ubel-mal":"bin/mal.js","ubel-npm":"bin/npm.js","ubel-cicd":"bin/cicd.js","ubel-pnpm":"bin/pnpm.js","ubel-sast":"bin/sast.js","ubel-yarn":"bin/yarn.js","ubel-agent":"bin/agent.js","ubel-chunk":"bin/chunk.js","ubel-docker":"bin/docker.js","ubel-license":"bin/license.js","ubel-secrets":"bin/secrets.js","ubel-platform":"bin/platform.js"},"dist":{"shasum":"03a47e87e12d4d15b75b6a4df0c155529492dd0a","tarball":"https://registry.npmjs.org/@arcane-spark/ubel-node/-/ubel-node-0.10.0.tgz","fileCount":93,"integrity":"sha512-xUy+CvMASNeZrwUpqJGu94FYY1toFsGwOJd77b5ZFWFveS/bLJ+eI9vBh+gpfsEPIpP0E9zJP3SEnvMwyo7gsw==","signatures":[{"sig":"MEYCIQDT3M/UWKf/81pLCCidKXu3uHWJl/ZbSbHOpzVCm90E8QIhAO+zjC95dlr+Vvw7WRim5Kqdu6Y6/nKnQBio0HNf0A6f","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1229803},"main":"sca/main.js","type":"module","engines":{"node":">=18.0.0"},"exports":{"./sca":"./sca/main.js","./sast":"./sast/main.js"},"gitHead":"420de63ebf809e7d2ffae16f471965ab7e24c4a8","scripts":{},"_npmUser":{"name":"alabouali","email":"ala.bouali.1997@gmail.com"},"repository":{"url":"git+https://github.com/AlaBouali/ubel.git","type":"git","directory":"node"},"_npmVersion":"10.8.0","description":"Software supply-chain and source-code security for Node.js. SCA: resolves dependencies, scans via OSV.dev and NVD, and annotates findings with heuristic reachability (SBOM/CycloneDX + SARIF reporting). Firewall: gates npm/pnpm/bun installs behind a lockfi","directories":{},"_nodeVersion":"22.16.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ubel-node_0.10.0_1785940295651_0.36016040893402623","host":"s3://npm-registry-packages-npm-production"}},"0.11.0":{"name":"@arcane-spark/ubel-node","version":"0.11.0","keywords":["security","supply-chain","vulnerability","audit","firewall","sbom","osv","nvd","npm","pnpm","bun","dependencies","policy","sca","cve","compliance","scanner","infection","malware","yarn","devsecops","cvss","lockfile","cyclonedx","sast","secrets","secret scanning","credential detection","grc","devops","devsecops","sarif","license","license compliance","backdoor","supply chain","software composition analysis","software supply chain","information security","application security","application security testing","appsec","iac","infrastructure as code","docker","container security","pip","uv","pypi","python","pipx","apt","dnf","yum","linux firewall"],"author":{"name":"Ala Bouali","email":"ala.bouali.1997@gmail.com"},"license":"SEE LICENSE IN LICENSE.md","_id":"@arcane-spark/ubel-node@0.11.0","maintainers":[{"name":"alabouali","email":"ala.bouali.1997@gmail.com"}],"homepage":"https://github.com/AlaBouali/ubel#readme","bugs":{"url":"https://github.com/AlaBouali/ubel/issues"},"bin":{"ubel-uv":"bin/uv.js","ubel-apt":"bin/apt.js","ubel-bun":"bin/bun.js","ubel-dnf":"bin/dnf.js","ubel-mal":"bin/mal.js","ubel-npm":"bin/npm.js","ubel-pip":"bin/pip.js","ubel-yum":"bin/yum.js","ubel-cicd":"bin/cicd.js","ubel-pipx":"bin/pipx.js","ubel-pnpm":"bin/pnpm.js","ubel-sast":"bin/sast.js","ubel-yarn":"bin/yarn.js","ubel-agent":"bin/agent.js","ubel-chunk":"bin/chunk.js","ubel-docker":"bin/docker.js","ubel-license":"bin/license.js","ubel-secrets":"bin/secrets.js","ubel-platform":"bin/platform.js"},"dist":{"shasum":"6552d1ae44674ceec82b8c49cca843ca4da52dc7","tarball":"https://registry.npmjs.org/@arcane-spark/ubel-node/-/ubel-node-0.11.0.tgz","fileCount":100,"integrity":"sha512-zFiYbqg/uu4RuDFzz+Wj5MnnFPChQqNWN+a7aqI0BlD2wXi8dfcXVKXr9ouvx7ab557hhw+jbMqKbI1ePcy6OA==","signatures":[{"sig":"MEQCIGzyjEim2Aoq4O7KWgqE8+lAfh+GyYaVrih9914YtofwAiBjAVcV19yx6g39yT3b9s6o3/ic+4wuHZOyjK4dXVpe3A==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1351656},"main":"sca/main.js","type":"module","engines":{"node":">=18.0.0"},"exports":{"./sca":"./sca/main.js","./sast":"./sast/main.js"},"gitHead":"4a3b95e29e6bd2972969fc329a68c6d7f1decbae","scripts":{},"_npmUser":{"name":"alabouali","email":"ala.bouali.1997@gmail.com"},"repository":{"url":"git+https://github.com/AlaBouali/ubel.git","type":"git","directory":"node"},"_npmVersion":"10.8.0","description":"Software supply-chain and source-code security for Node.js. SCA: resolves dependencies, scans via OSV.dev and NVD, and annotates findings with heuristic reachability (SBOM/CycloneDX + SARIF reporting). Firewall: gates npm/pnpm/bun installs behind a lockfi","directories":{},"_nodeVersion":"22.16.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ubel-node_0.11.0_1786628842498_0.7283224264150352","host":"s3://npm-registry-packages-npm-production"}},"0.12.0":{"name":"@arcane-spark/ubel-node","version":"0.12.0","keywords":["security","supply-chain","vulnerability","audit","firewall","sbom","osv","nvd","npm","pnpm","bun","dependencies","policy","sca","cve","compliance","scanner","infection","malware","yarn","devsecops","cvss","lockfile","cyclonedx","sast","secrets","secret scanning","credential detection","grc","devops","devsecops","sarif","license","license compliance","backdoor","supply chain","software composition analysis","software supply chain","information security","application security","application security testing","appsec","iac","infrastructure as code","docker","container security","pip","uv","pypi","python","pipx","apt","dnf","yum","linux firewall"],"author":{"name":"Ala Bouali","email":"ala.bouali.1997@gmail.com"},"license":"SEE LICENSE IN LICENSE.md","_id":"@arcane-spark/ubel-node@0.12.0","maintainers":[{"name":"alabouali","email":"ala.bouali.1997@gmail.com"}],"homepage":"https://github.com/AlaBouali/ubel#readme","bugs":{"url":"https://github.com/AlaBouali/ubel/issues"},"bin":{"ubel-uv":"bin/uv.js","ubel-apt":"bin/apt.js","ubel-bun":"bin/bun.js","ubel-dnf":"bin/dnf.js","ubel-mal":"bin/mal.js","ubel-npm":"bin/npm.js","ubel-pip":"bin/pip.js","ubel-yum":"bin/yum.js","ubel-cicd":"bin/cicd.js","ubel-pipx":"bin/pipx.js","ubel-pnpm":"bin/pnpm.js","ubel-sast":"bin/sast.js","ubel-yarn":"bin/yarn.js","ubel-agent":"bin/agent.js","ubel-chunk":"bin/chunk.js","ubel-docker":"bin/docker.js","ubel-license":"bin/license.js","ubel-secrets":"bin/secrets.js","ubel-composer":"bin/composer.js","ubel-platform":"bin/platform.js"},"dist":{"shasum":"a6110b1cf26969dc1335864c32f93ac817a31c71","tarball":"https://registry.npmjs.org/@arcane-spark/ubel-node/-/ubel-node-0.12.0.tgz","fileCount":108,"integrity":"sha512-UYBRuInK20oh9hDnW0TjRLaBMmwRJtg1l83mt7kM620KpaRwJoWYXG96AwWy5wkkb6nfZb28H8V/qqeE3gIe/w==","signatures":[{"sig":"MEUCICH9A127gZ7xdtVqhB/nUGg2VcUrLNirf5oAENv7aaISAiEAqBY7S3K2KVG51SIp4URRBwHeTfcpcQzBZjM+bdntbdo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2034391},"main":"sca/main.js","type":"module","engines":{"node":">=18.0.0"},"exports":{"./sca":"./sca/main.js","./sast":"./sast/main.js"},"gitHead":"468866c742d9e2528d07638da42cc6bcdbff7400","scripts":{},"_npmUser":{"name":"alabouali","email":"ala.bouali.1997@gmail.com"},"repository":{"url":"git+https://github.com/AlaBouali/ubel.git","type":"git","directory":"node"},"_npmVersion":"10.8.0","description":"Software supply-chain and source-code security for Node.js. SCA: resolves dependencies, scans via OSV.dev and NVD, and annotates findings with heuristic reachability (SBOM/CycloneDX + SARIF reporting). Firewall: gates npm/pnpm/bun installs behind a lockfi","directories":{},"_nodeVersion":"22.16.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ubel-node_0.12.0_1788876030650_0.728091511493099","host":"s3://npm-registry-packages-npm-production"}},"0.13.0":{"name":"@arcane-spark/ubel-node","version":"0.13.0","keywords":["security","supply-chain","vulnerability","audit","firewall","sbom","osv","nvd","npm","pnpm","bun","dependencies","policy","sca","cve","compliance","scanner","infection","malware","yarn","devsecops","cvss","lockfile","cyclonedx","sast","secrets","secret scanning","credential detection","grc","devops","devsecops","sarif","license","license compliance","backdoor","supply chain","software composition analysis","software supply chain","information security","application security","application security testing","appsec","iac","infrastructure as code","docker","container security","pip","uv","pypi","python","pipx","apt","dnf","yum","linux firewall","cloud security","cloud misconfiguration","cspm","aws","gcp","azure","iam","encryption","audit logging","public exposure","misconfiguration","misconfig","cloud posture","cloud security posture management","cspm","soc2","iso27001","hipaa","pci dss","nist"],"author":{"name":"Ala Bouali","email":"ala.bouali.1997@gmail.com"},"license":"SEE LICENSE IN LICENSE.md","_id":"@arcane-spark/ubel-node@0.13.0","maintainers":[{"name":"alabouali","email":"ala.bouali.1997@gmail.com"}],"homepage":"https://github.com/AlaBouali/ubel#readme","bugs":{"url":"https://github.com/AlaBouali/ubel/issues"},"bin":{"ubel-uv":"bin/uv.js","ubel-apt":"bin/apt.js","ubel-bun":"bin/bun.js","ubel-dnf":"bin/dnf.js","ubel-mal":"bin/mal.js","ubel-npm":"bin/npm.js","ubel-pip":"bin/pip.js","ubel-yum":"bin/yum.js","ubel-cicd":"bin/cicd.js","ubel-pipx":"bin/pipx.js","ubel-pnpm":"bin/pnpm.js","ubel-sast":"bin/sast.js","ubel-yarn":"bin/yarn.js","ubel-agent":"bin/agent.js","ubel-chunk":"bin/chunk.js","ubel-cloud":"bin/cloud.js","ubel-docker":"bin/docker.js","ubel-license":"bin/license.js","ubel-secrets":"bin/secrets.js","ubel-composer":"bin/composer.js","ubel-platform":"bin/platform.js"},"dist":{"shasum":"2213dea826f2ddeb0036bd069d70b32904b5d489","tarball":"https://registry.npmjs.org/@arcane-spark/ubel-node/-/ubel-node-0.13.0.tgz","fileCount":154,"integrity":"sha512-5/QLoXygpGZQbD0h+Qi+Np8utzYt4vdqUa4r/+uUenNe4BIrvsVl+Ns0zAx41lEhNOrZ0YJ28+OjHE06Q7r5vQ==","signatures":[{"sig":"MEUCIEPSLMFQcIbG63j2dc7Ni9MZdBHojKr+a8QK/8099uBbAiEAremWetLnczxprkWcgEGZXjh4PeMRjyOzmjDAUWiWH08=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIDI6Nb+hl2fXK5PCnxFamAFrvKXY6IBYg6ykxVgrNg9VAiBpxTuxXjW5fMKsz2uWBLjLa3OJ663NGsWLfZiNhtk6iQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2386443},"main":"sca/main.js","type":"module","engines":{"node":">=18.0.0"},"exports":{"./sca":"./sca/main.js","./sast":"./sast/main.js"},"gitHead":"e9e3d4827dc860e5a102b62ae504a20e4b933032","scripts":{},"_npmUser":{"name":"alabouali","email":"ala.bouali.1997@gmail.com"},"repository":{"url":"git+https://github.com/AlaBouali/ubel.git","type":"git","directory":"node"},"_npmVersion":"10.8.0","description":"Software supply-chain and source-code security for Node.js. SCA: resolves dependencies, scans via OSV.dev and NVD, and annotates findings with heuristic reachability (SBOM/CycloneDX + SARIF reporting). Firewall: gates npm/pnpm/bun installs behind a lockfi","directories":{},"_nodeVersion":"22.16.0","dependencies":{},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ubel-node_0.13.0_1789244416862_0.8174748862075119","host":"s3://npm-registry-packages-npm-production"}},"0.13.1":{"name":"@arcane-spark/ubel-node","version":"0.13.1","keywords":["security","supply-chain","vulnerability","audit","firewall","sbom","osv","nvd","npm","pnpm","bun","dependencies","policy","sca","cve","compliance","scanner","infection","malware","yarn","devsecops","cvss","lockfile","cyclonedx","sast","secrets","secret scanning","credential detection","grc","devops","devsecops","sarif","license","license compliance","backdoor","supply chain","software composition analysis","software supply chain","information security","application security","application security testing","appsec","iac","infrastructure as code","docker","container security","pip","uv","pypi","python","pipx","apt","dnf","yum","linux firewall","cloud security","cloud misconfiguration","cspm","aws","gcp","azure","iam","encryption","audit logging","public exposure","misconfiguration","misconfig","cloud posture","cloud security posture management","cspm","soc2","iso27001","hipaa","pci dss","nist"],"author":{"name":"Ala Bouali","email":"ala.bouali.1997@gmail.com"},"license":"SEE LICENSE IN LICENSE.md","_id":"@arcane-spark/ubel-node@0.13.1","maintainers":[{"name":"alabouali","email":"ala.bouali.1997@gmail.com"}],"homepage":"https://github.com/AlaBouali/ubel#readme","bugs":{"url":"https://github.com/AlaBouali/ubel/issues"},"bin":{"ubel-uv":"bin/uv.js","ubel-apt":"bin/apt.js","ubel-bun":"bin/bun.js","ubel-dnf":"bin/dnf.js","ubel-mal":"bin/mal.js","ubel-npm":"bin/npm.js","ubel-pip":"bin/pip.js","ubel-yum":"bin/yum.js","ubel-cicd":"bin/cicd.js","ubel-pipx":"bin/pipx.js","ubel-pnpm":"bin/pnpm.js","ubel-sast":"bin/sast.js","ubel-yarn":"bin/yarn.js","ubel-agent":"bin/agent.js","ubel-chunk":"bin/chunk.js","ubel-cloud":"bin/cloud.js","ubel-docker":"bin/docker.js","ubel-license":"bin/license.js","ubel-secrets":"bin/secrets.js","ubel-composer":"bin/composer.js","ubel-platform":"bin/platform.js"},"dist":{"shasum":"7be6ef53858e8ca9cfcf55f1eaeddea1384f21bf","tarball":"https://registry.npmjs.org/@arcane-spark/ubel-node/-/ubel-node-0.13.1.tgz","fileCount":154,"integrity":"sha512-cn+lpv8jEPaZQHmUvNRJ8WVkXvU3zzVhlhx6+D8/K/7KubzROaqc+/SkUdyNLubK7GX9UwGYQMigZTRmRW6JsA==","signatures":[{"sig":"MEUCIQDOO6+ijD+whvxczLmS/b6EFhPdGA8t509GZjX7vAygTgIgbmOKxSRdWSgCfEsOxhfNEh9AFtuwvUvMmptzX7ydXbU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQDMh3Ch0PcAE/Zmn1Jo/T6POV+LtqrrkdyNchiBmpDGjAIhAIyBjqs3OOnV+6mOAGvnHrDkxD3WIHuLrnJQFjht9e8D","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2386492},"main":"sca/main.js","type":"module","engines":{"node":">=18.0.0"},"exports":{"./sca":"./sca/main.js","./sast":"./sast/main.js"},"gitHead":"7a3e1408a7d1138dd66a45fb5248398a289f1f9e","scripts":{},"_npmUser":{"name":"alabouali","email":"ala.bouali.1997@gmail.com"},"repository":{"url":"git+https://github.com/AlaBouali/ubel.git","type":"git","directory":"node"},"_npmVersion":"10.8.0","description":"Software supply-chain and source-code security for Node.js. SCA: resolves dependencies, scans via OSV.dev and NVD, and annotates findings with heuristic reachability (SBOM/CycloneDX + SARIF reporting). Firewall: gates npm/pnpm/bun installs behind a lockfi","directories":{},"_nodeVersion":"22.16.0","dependencies":{},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ubel-node_0.13.1_1789246469958_0.7691102943815387","host":"s3://npm-registry-packages-npm-production"}},"0.14.0":{"name":"@arcane-spark/ubel-node","version":"0.14.0","keywords":["security","supply-chain","vulnerability","audit","firewall","sbom","osv","nvd","npm","pnpm","bun","dependencies","policy","sca","cve","compliance","scanner","infection","malware","yarn","devsecops","cvss","lockfile","cyclonedx","sast","secrets","secret scanning","credential detection","grc","devops","devsecops","sarif","license","license compliance","backdoor","supply chain","software composition analysis","software supply chain","information security","application security","application security testing","appsec","iac","infrastructure as code","docker","container security","pip","uv","pypi","python","pipx","apt","dnf","yum","linux firewall","cloud security","cloud misconfiguration","cspm","aws","gcp","azure","iam","encryption","audit logging","public exposure","misconfiguration","misconfig","cloud posture","cloud security posture management","cspm","easm","external attack surface management","attack surface","fingerprinting","cpe","recon","soc2","iso27001","hipaa","pci dss","nist"],"author":{"name":"Ala Bouali","email":"ala.bouali.1997@gmail.com"},"license":"SEE LICENSE IN LICENSE.md","_id":"@arcane-spark/ubel-node@0.14.0","maintainers":[{"name":"alabouali","email":"ala.bouali.1997@gmail.com"}],"homepage":"https://github.com/AlaBouali/ubel#readme","bugs":{"url":"https://github.com/AlaBouali/ubel/issues"},"bin":{"ubel-uv":"bin/uv.js","ubel-apt":"bin/apt.js","ubel-bun":"bin/bun.js","ubel-dnf":"bin/dnf.js","ubel-mal":"bin/mal.js","ubel-npm":"bin/npm.js","ubel-pip":"bin/pip.js","ubel-url":"bin/url.js","ubel-yum":"bin/yum.js","ubel-cicd":"bin/cicd.js","ubel-pipx":"bin/pipx.js","ubel-pnpm":"bin/pnpm.js","ubel-sast":"bin/sast.js","ubel-yarn":"bin/yarn.js","ubel-agent":"bin/agent.js","ubel-chunk":"bin/chunk.js","ubel-cloud":"bin/cloud.js","ubel-docker":"bin/docker.js","ubel-domain":"bin/domain.js","ubel-license":"bin/license.js","ubel-secrets":"bin/secrets.js","ubel-composer":"bin/composer.js","ubel-platform":"bin/platform.js"},"dist":{"shasum":"2a91c4c56b85a4eecfcdcea9ff3c7a5ef1c92038","tarball":"https://registry.npmjs.org/@arcane-spark/ubel-node/-/ubel-node-0.14.0.tgz","fileCount":251,"integrity":"sha512-8rN/E79Bc574eL0FNJVp/XeP+k+jlx0AQlWrzDIrBWKzRZE2av61YcPNjC6C+f53Y2+na/uXLlx+qPtkhdYVsg==","signatures":[{"sig":"MEYCIQC3+iNNH26Ql4bY8z7s0Q2CVwCAsJ+klq4SSJFsvbUn0AIhAL3OSm/KuG/Kmpqgwa8R0zqSzOKNq+K/6M9a0R1Yjzen","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQDvucTGXOTF31GIdrvLVLKo7t2/Tl4Dr+KgfJ0YOqZnwgIhAMgXPaJkwYwKa5Psw1yHTto90ZOUZLGAdk0b65E++d82","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2805315},"main":"sca/main.js","type":"module","engines":{"node":">=18.0.0"},"exports":{"./sca":"./sca/main.js","./sast":"./sast/main.js"},"gitHead":"ad8c08a74e80f0c1c6cdf2d7289d149db04a887b","scripts":{},"_npmUser":{"name":"alabouali","email":"ala.bouali.1997@gmail.com"},"repository":{"url":"git+https://github.com/AlaBouali/ubel.git","type":"git","directory":"node"},"_npmVersion":"10.8.0","description":"Software supply-chain and source-code security for Node.js. SCA: resolves dependencies, scans via OSV.dev and NVD, and annotates findings with heuristic reachability (SBOM/CycloneDX + SARIF reporting). Firewall: gates npm/pnpm/bun installs behind a lockfi","directories":{},"_nodeVersion":"22.16.0","dependencies":{},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ubel-node_0.14.0_1789690692106_0.11594108786472912","host":"s3://npm-registry-packages-npm-production"}},"0.14.1":{"name":"@arcane-spark/ubel-node","version":"0.14.1","keywords":["security","supply-chain","vulnerability","audit","firewall","sbom","osv","nvd","npm","pnpm","bun","dependencies","policy","sca","cve","compliance","scanner","infection","malware","yarn","devsecops","cvss","lockfile","cyclonedx","sast","secrets","secret scanning","credential detection","grc","devops","devsecops","sarif","license","license compliance","backdoor","supply chain","software composition analysis","software supply chain","information security","application security","application security testing","appsec","iac","infrastructure as code","docker","container security","pip","uv","pypi","python","pipx","apt","dnf","yum","linux firewall","cloud security","cloud misconfiguration","cspm","aws","gcp","azure","iam","encryption","audit logging","public exposure","misconfiguration","misconfig","cloud posture","cloud security posture management","cspm","easm","external attack surface management","attack surface","fingerprinting","cpe","recon","soc2","iso27001","hipaa","pci dss","nist"],"author":{"name":"Ala Bouali","email":"ala.bouali.1997@gmail.com"},"license":"SEE LICENSE IN LICENSE.md","_id":"@arcane-spark/ubel-node@0.14.1","maintainers":[{"name":"alabouali","email":"ala.bouali.1997@gmail.com"}],"homepage":"https://github.com/AlaBouali/ubel#readme","bugs":{"url":"https://github.com/AlaBouali/ubel/issues"},"bin":{"ubel-uv":"bin/uv.js","ubel-apt":"bin/apt.js","ubel-bun":"bin/bun.js","ubel-dnf":"bin/dnf.js","ubel-mal":"bin/mal.js","ubel-npm":"bin/npm.js","ubel-pip":"bin/pip.js","ubel-url":"bin/url.js","ubel-yum":"bin/yum.js","ubel-cicd":"bin/cicd.js","ubel-pipx":"bin/pipx.js","ubel-pnpm":"bin/pnpm.js","ubel-sast":"bin/sast.js","ubel-yarn":"bin/yarn.js","ubel-agent":"bin/agent.js","ubel-chunk":"bin/chunk.js","ubel-cloud":"bin/cloud.js","ubel-docker":"bin/docker.js","ubel-domain":"bin/domain.js","ubel-license":"bin/license.js","ubel-secrets":"bin/secrets.js","ubel-composer":"bin/composer.js","ubel-platform":"bin/platform.js"},"dist":{"shasum":"766efa169fb7ebd872251b7d5e1ac916148d0c73","tarball":"https://registry.npmjs.org/@arcane-spark/ubel-node/-/ubel-node-0.14.1.tgz","fileCount":251,"integrity":"sha512-w0w6ShKCT2BVTHF1H+nVz1FmA8L0do5WQamWrREoRnPrc7+Wr7oHcCalJ6iuZj2Ca1cuPnNyFD8nBoZxD52JWg==","signatures":[{"sig":"MEUCIQDnMmOiqFftr2oXCio2BmXhSHJt1MOfrRnxNqAcAjp5BgIgPxpUaJ+lx8/GwShmHx5XciFfGDVRwtMKfJ8LO5UCqiQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQDA6AdnIuHhyAJIqurP0ulBGeZ40Uj1Uj1Itrn8lNUOxgIgA2CsAsnaWl/EnnONhfw5wMGdvL7XX0VwiWlFu2dQ78E=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2825541},"main":"sca/main.js","type":"module","engines":{"node":">=18.0.0"},"exports":{"./sca":"./sca/main.js","./sast":"./sast/main.js"},"gitHead":"5657ca4abdb231416dbc72d6ded477d9c7c0c328","scripts":{},"_npmUser":{"name":"alabouali","email":"ala.bouali.1997@gmail.com"},"repository":{"url":"git+https://github.com/AlaBouali/ubel.git","type":"git","directory":"node"},"_npmVersion":"10.8.0","description":"Software supply-chain and source-code security for Node.js. SCA: resolves dependencies, scans via OSV.dev and NVD, and annotates findings with heuristic reachability (SBOM/CycloneDX + SARIF reporting). Firewall: gates npm/pnpm/bun installs behind a lockfi","directories":{},"_nodeVersion":"22.16.0","dependencies":{},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ubel-node_0.14.1_1789737979374_0.5777436686867266","host":"s3://npm-registry-packages-npm-production"}},"0.14.2":{"name":"@arcane-spark/ubel-node","version":"0.14.2","keywords":["security","supply-chain","vulnerability","audit","firewall","sbom","osv","nvd","npm","pnpm","bun","dependencies","policy","sca","cve","compliance","scanner","infection","malware","yarn","devsecops","cvss","lockfile","cyclonedx","sast","secrets","secret scanning","credential detection","grc","devops","devsecops","sarif","license","license compliance","backdoor","supply chain","software composition analysis","software supply chain","information security","application security","application security testing","appsec","iac","infrastructure as code","docker","container security","pip","uv","pypi","python","pipx","apt","dnf","yum","linux firewall","cloud security","cloud misconfiguration","cspm","aws","gcp","azure","iam","encryption","audit logging","public exposure","misconfiguration","misconfig","cloud posture","cloud security posture management","cspm","easm","external attack surface management","attack surface","fingerprinting","cpe","recon","soc2","iso27001","hipaa","pci dss","nist"],"author":{"name":"Ala Bouali","email":"ala.bouali.1997@gmail.com"},"license":"SEE LICENSE IN LICENSE.md","_id":"@arcane-spark/ubel-node@0.14.2","maintainers":[{"name":"alabouali","email":"ala.bouali.1997@gmail.com"}],"homepage":"https://github.com/AlaBouali/ubel#readme","bugs":{"url":"https://github.com/AlaBouali/ubel/issues"},"bin":{"ubel-uv":"bin/uv.js","ubel-apt":"bin/apt.js","ubel-bun":"bin/bun.js","ubel-dnf":"bin/dnf.js","ubel-mal":"bin/mal.js","ubel-npm":"bin/npm.js","ubel-pip":"bin/pip.js","ubel-url":"bin/url.js","ubel-yum":"bin/yum.js","ubel-cicd":"bin/cicd.js","ubel-pipx":"bin/pipx.js","ubel-pnpm":"bin/pnpm.js","ubel-sast":"bin/sast.js","ubel-yarn":"bin/yarn.js","ubel-agent":"bin/agent.js","ubel-chunk":"bin/chunk.js","ubel-cloud":"bin/cloud.js","ubel-docker":"bin/docker.js","ubel-domain":"bin/domain.js","ubel-license":"bin/license.js","ubel-secrets":"bin/secrets.js","ubel-composer":"bin/composer.js","ubel-platform":"bin/platform.js"},"dist":{"shasum":"ac000a3221434be60b22f8a4fcc5cf44c5c86974","tarball":"https://registry.npmjs.org/@arcane-spark/ubel-node/-/ubel-node-0.14.2.tgz","fileCount":251,"integrity":"sha512-mOCai2RSoiWTU7zotMUkZ6qTev8reKBgl0bq+0pRS19zpi3aKcuhAJdh3LHccyGFSeW9HI6n1ncz7OME/ua5XA==","signatures":[{"sig":"MEQCIFbimgeGQaBV2KQuhRUD8pt1Sb7rGATG43QYYIXwyV8ZAiADeu1cyjEDcH0FKlJ4bp6OR0U/5SLGIpfLYIM+MU0LdA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIB5Ttt+ha88yx4HsvGHis5eADR1OFmKPTpGlkBsKv41rAiBHPKs9GGF3ISmNPPnD1jVpUmKRFDKWzQJryHfCdsVOog==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2885304},"main":"sca/main.js","type":"module","engines":{"node":">=18.0.0"},"exports":{"./sca":"./sca/main.js","./sast":"./sast/main.js"},"gitHead":"aa6228f033225848aa0dff561e1b92bd3623d0b3","scripts":{},"_npmUser":{"name":"alabouali","email":"ala.bouali.1997@gmail.com"},"repository":{"url":"git+https://github.com/AlaBouali/ubel.git","type":"git","directory":"node"},"_npmVersion":"10.8.0","description":"Software supply-chain and source-code security for Node.js. SCA: resolves dependencies, scans via OSV.dev and NVD, and annotates findings with heuristic reachability (SBOM/CycloneDX + SARIF reporting). Firewall: gates npm/pnpm/bun installs behind a lockfi","directories":{},"_nodeVersion":"22.16.0","dependencies":{},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ubel-node_0.14.2_1789842085737_0.5769682339934181","host":"s3://npm-registry-packages-npm-production"}},"0.15.0":{"name":"@arcane-spark/ubel-node","version":"0.15.0","keywords":["security","supply-chain","vulnerability","audit","firewall","sbom","osv","nvd","npm","pnpm","bun","dependencies","policy","sca","cve","compliance","scanner","infection","malware","yarn","devsecops","cvss","lockfile","cyclonedx","sast","secrets","secret scanning","credential detection","grc","devops","devsecops","sarif","license","license compliance","backdoor","supply chain","software composition analysis","software supply chain","information security","application security","application security testing","appsec","iac","infrastructure as code","docker","container security","pip","uv","pypi","python","pipx","apt","dnf","yum","linux firewall","cloud security","cloud misconfiguration","cspm","aws","gcp","azure","iam","encryption","audit logging","public exposure","misconfiguration","misconfig","cloud posture","cloud security posture management","cspm","easm","external attack surface management","attack surface","fingerprinting","cpe","recon","subdomain discovery","certificate transparency","crt.sh","spf","dmarc","dkim","email security","email spoofing","phishing","cors","security headers","hsts","soc2","iso27001","hipaa","pci dss","nist"],"author":{"name":"Ala Bouali","email":"ala.bouali.1997@gmail.com"},"license":"SEE LICENSE IN LICENSE.md","_id":"@arcane-spark/ubel-node@0.15.0","maintainers":[{"name":"alabouali","email":"ala.bouali.1997@gmail.com"}],"homepage":"https://github.com/AlaBouali/ubel#readme","bugs":{"url":"https://github.com/AlaBouali/ubel/issues"},"bin":{"ubel-uv":"bin/uv.js","ubel-apt":"bin/apt.js","ubel-bun":"bin/bun.js","ubel-dnf":"bin/dnf.js","ubel-mal":"bin/mal.js","ubel-npm":"bin/npm.js","ubel-pip":"bin/pip.js","ubel-url":"bin/url.js","ubel-yum":"bin/yum.js","ubel-cicd":"bin/cicd.js","ubel-pipx":"bin/pipx.js","ubel-pnpm":"bin/pnpm.js","ubel-sast":"bin/sast.js","ubel-yarn":"bin/yarn.js","ubel-agent":"bin/agent.js","ubel-chunk":"bin/chunk.js","ubel-cloud":"bin/cloud.js","ubel-docker":"bin/docker.js","ubel-domain":"bin/domain.js","ubel-license":"bin/license.js","ubel-secrets":"bin/secrets.js","ubel-composer":"bin/composer.js","ubel-platform":"bin/platform.js"},"dist":{"shasum":"deda1b897fad2bd969376a4e1989bd0868f78a24","tarball":"https://registry.npmjs.org/@arcane-spark/ubel-node/-/ubel-node-0.15.0.tgz","fileCount":251,"integrity":"sha512-ZDZJwhdCL2lWGwLU+fpuWJRw35vwzLOzp8MynEITvjDswBOcWb2eEGwq3xllnEZHXwNlUIauoRiZvdtEi6wbyA==","signatures":[{"sig":"MEYCIQCpw/2Jlqxt55Aa8yP1B50OZyWPEFe7J1aoScCny55kIwIhAJC751L0dfBL3eDmKJtpl9ptYxOBuh3QDngOIMOpupzP","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCICf7njer3U4PWegsVKbXgkBavc13da+f1pGwUpI+t6mCAiAyslOfvXmCPocTNtynsKvrgyBSHNEz4jgDxdMTuS29Ng==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2912803},"main":"sca/main.js","type":"module","engines":{"node":">=18.0.0"},"exports":{"./sca":"./sca/main.js","./sast":"./sast/main.js"},"gitHead":"1f650c57038a735d13aee65254e9ca70b0634b87","scripts":{},"_npmUser":{"name":"alabouali","email":"ala.bouali.1997@gmail.com"},"repository":{"url":"git+https://github.com/AlaBouali/ubel.git","type":"git","directory":"node"},"_npmVersion":"10.8.0","description":"Software supply-chain and source-code security for Node.js. SCA: resolves dependencies, scans via OSV.dev and NVD, and annotates findings with heuristic reachability (SBOM/CycloneDX + SARIF reporting). Firewall: gates npm/pnpm/bun installs behind a lockfi","directories":{},"_nodeVersion":"22.16.0","dependencies":{},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ubel-node_0.15.0_1789845123131_0.800280350002676","host":"s3://npm-registry-packages-npm-production"}},"0.16.0":{"name":"@arcane-spark/ubel-node","version":"0.16.0","keywords":["security","supply-chain","vulnerability","audit","firewall","sbom","osv","nvd","npm","pnpm","bun","dependencies","policy","sca","cve","compliance","scanner","infection","malware","yarn","devsecops","cvss","lockfile","cyclonedx","sast","secrets","secret scanning","credential detection","grc","devops","devsecops","sarif","license","license compliance","backdoor","supply chain","software composition analysis","software supply chain","information security","application security","application security testing","appsec","iac","infrastructure as code","docker","container security","pip","uv","pypi","python","pipx","apt","dnf","yum","linux firewall","cloud security","cloud misconfiguration","cspm","aws","gcp","azure","iam","encryption","audit logging","public exposure","misconfiguration","misconfig","cloud posture","cloud security posture management","cspm","easm","external attack surface management","attack surface","fingerprinting","cpe","recon","subdomain discovery","certificate transparency","crt.sh","spf","dmarc","dkim","email security","email spoofing","phishing","cors","security headers","hsts","soc2","iso27001","hipaa","pci dss","nist"],"author":{"name":"Ala Bouali","email":"ala.bouali.1997@gmail.com"},"license":"SEE LICENSE IN LICENSE.md","_id":"@arcane-spark/ubel-node@0.16.0","maintainers":[{"name":"alabouali","email":"ala.bouali.1997@gmail.com"}],"homepage":"https://github.com/AlaBouali/ubel#readme","bugs":{"url":"https://github.com/AlaBouali/ubel/issues"},"bin":{"ubel-uv":"bin/uv.js","ubel-apt":"bin/apt.js","ubel-bun":"bin/bun.js","ubel-dnf":"bin/dnf.js","ubel-mal":"bin/mal.js","ubel-npm":"bin/npm.js","ubel-pip":"bin/pip.js","ubel-url":"bin/url.js","ubel-yum":"bin/yum.js","ubel-cicd":"bin/cicd.js","ubel-easm":"bin/easm.js","ubel-host":"bin/host.js","ubel-pipx":"bin/pipx.js","ubel-pnpm":"bin/pnpm.js","ubel-sast":"bin/sast.js","ubel-yarn":"bin/yarn.js","ubel-agent":"bin/agent.js","ubel-chunk":"bin/chunk.js","ubel-cloud":"bin/cloud.js","ubel-docker":"bin/docker.js","ubel-domain":"bin/domain.js","ubel-license":"bin/license.js","ubel-secrets":"bin/secrets.js","ubel-composer":"bin/composer.js","ubel-platform":"bin/platform.js"},"dist":{"shasum":"f418816bcf3deefe0ad7ff268a3805589ccbf571","tarball":"https://registry.npmjs.org/@arcane-spark/ubel-node/-/ubel-node-0.16.0.tgz","fileCount":256,"integrity":"sha512-DLLeQ1Pu07+ecK9IYZL1gU2pE8tkjPKKoRs4v0VDf/tOBpnMK7dCvk9+pVdSPBkMrR9P//Rvl8LcUg3oVpAopA==","signatures":[{"sig":"MEQCIFArnuVaeHtRWZ/xt2uULWgc3uaX7k2UieJ68WF6qViBAiANDO8OhHY5ZtnrLmGSCH/FlOSVmlEnjVZX/uMvnCB4hw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQC9aTOnkD3JKZyUl+Um6FXS4owOmKno9KP+mwBHWRo39AIhAM+BrJCcYTLSFMtqhPbgEfel7EAeButvZlDC8EmGD3Uk","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":3021069},"main":"sca/main.js","type":"module","engines":{"node":">=18.0.0"},"exports":{"./sca":"./sca/main.js","./sast":"./sast/main.js"},"gitHead":"ed362f0b78d2b9aa84edb32af2dd6823aa524007","scripts":{},"_npmUser":{"name":"alabouali","email":"ala.bouali.1997@gmail.com"},"repository":{"url":"git+https://github.com/AlaBouali/ubel.git","type":"git","directory":"node"},"_npmVersion":"10.8.0","description":"Software supply-chain and source-code security for Node.js. SCA: resolves dependencies, scans via OSV.dev and NVD, and annotates findings with heuristic reachability (SBOM/CycloneDX + SARIF reporting). Firewall: gates npm/pnpm/bun installs behind a lockfi","directories":{},"_nodeVersion":"22.16.0","dependencies":{},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ubel-node_0.16.0_1789932937221_0.5055472871300448","host":"s3://npm-registry-packages-npm-production"}},"0.16.1":{"name":"@arcane-spark/ubel-node","version":"0.16.1","keywords":["security","supply-chain","vulnerability","audit","firewall","sbom","osv","nvd","npm","pnpm","bun","dependencies","policy","sca","cve","compliance","scanner","infection","malware","yarn","devsecops","cvss","lockfile","cyclonedx","sast","secrets","secret scanning","credential detection","grc","devops","devsecops","sarif","license","license compliance","backdoor","supply chain","software composition analysis","software supply chain","information security","application security","application security testing","appsec","iac","infrastructure as code","docker","container security","pip","uv","pypi","python","pipx","apt","dnf","yum","linux firewall","cloud security","cloud misconfiguration","cspm","aws","gcp","azure","iam","encryption","audit logging","public exposure","misconfiguration","misconfig","cloud posture","cloud security posture management","cspm","easm","external attack surface management","attack surface","fingerprinting","cpe","recon","subdomain discovery","certificate transparency","crt.sh","spf","dmarc","dkim","email security","email spoofing","phishing","cors","security headers","hsts","soc2","iso27001","hipaa","pci dss","nist"],"author":{"name":"Ala Bouali","email":"ala.bouali.1997@gmail.com"},"license":"SEE LICENSE IN LICENSE.md","_id":"@arcane-spark/ubel-node@0.16.1","maintainers":[{"name":"alabouali","email":"ala.bouali.1997@gmail.com"}],"homepage":"https://github.com/AlaBouali/ubel#readme","bugs":{"url":"https://github.com/AlaBouali/ubel/issues"},"bin":{"ubel-uv":"bin/uv.js","ubel-apt":"bin/apt.js","ubel-bun":"bin/bun.js","ubel-dnf":"bin/dnf.js","ubel-mal":"bin/mal.js","ubel-npm":"bin/npm.js","ubel-pip":"bin/pip.js","ubel-url":"bin/url.js","ubel-yum":"bin/yum.js","ubel-cicd":"bin/cicd.js","ubel-easm":"bin/easm.js","ubel-host":"bin/host.js","ubel-pipx":"bin/pipx.js","ubel-pnpm":"bin/pnpm.js","ubel-sast":"bin/sast.js","ubel-yarn":"bin/yarn.js","ubel-agent":"bin/agent.js","ubel-chunk":"bin/chunk.js","ubel-cloud":"bin/cloud.js","ubel-docker":"bin/docker.js","ubel-domain":"bin/domain.js","ubel-license":"bin/license.js","ubel-secrets":"bin/secrets.js","ubel-composer":"bin/composer.js","ubel-platform":"bin/platform.js"},"dist":{"shasum":"d7c7d473a21edf44649090796c2935d50d15ae8f","tarball":"https://registry.npmjs.org/@arcane-spark/ubel-node/-/ubel-node-0.16.1.tgz","fileCount":256,"integrity":"sha512-PhmUjXgDj3L7joQYmxABY/hn4SzSKzsysvdSIIugObAhnnTsl5KuuntAOJJ6TmbnmoMXalRjRNyzTB7kzpNzrQ==","signatures":[{"sig":"MEUCID2nrKdFrfd2UEfkKYOh0bXdo0YPXCzLrGdt07Mz/edHAiEAi0tl4KvHj2+qj2EMvtHKxU+awmlTeVZIPZ7WqO5WmLQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIANj7AZ0oyehphVWt4Hdbn8RV1gk5yAduhioGu5Dt0JLAiEAgrkSBWlZs8whqhAykVWpWqEnY7eWJCO7DmCGXdxiMpo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":3025463},"main":"sca/main.js","type":"module","engines":{"node":">=18.0.0"},"exports":{"./sca":"./sca/main.js","./sast":"./sast/main.js"},"gitHead":"ed362f0b78d2b9aa84edb32af2dd6823aa524007","scripts":{},"_npmUser":{"name":"alabouali","email":"ala.bouali.1997@gmail.com"},"repository":{"url":"git+https://github.com/AlaBouali/ubel.git","type":"git","directory":"node"},"_npmVersion":"10.8.0","description":"Software supply-chain and source-code security for Node.js. SCA: resolves dependencies, scans via OSV.dev and NVD, and annotates findings with heuristic reachability (SBOM/CycloneDX + SARIF reporting). Firewall: gates npm/pnpm/bun installs behind a lockfi","directories":{},"_nodeVersion":"22.16.0","dependencies":{},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ubel-node_0.16.1_1789948726988_0.27588850412688815","host":"s3://npm-registry-packages-npm-production"}},"0.16.2":{"name":"@arcane-spark/ubel-node","version":"0.16.2","keywords":["security","supply-chain","vulnerability","audit","firewall","sbom","osv","nvd","npm","pnpm","bun","dependencies","policy","sca","cve","compliance","scanner","infection","malware","yarn","devsecops","cvss","lockfile","cyclonedx","sast","secrets","secret scanning","credential detection","grc","devops","devsecops","sarif","license","license compliance","backdoor","supply chain","software composition analysis","software supply chain","information security","application security","application security testing","appsec","iac","infrastructure as code","docker","container security","pip","uv","pypi","python","pipx","apt","dnf","yum","linux firewall","cloud security","cloud misconfiguration","cspm","aws","gcp","azure","iam","encryption","audit logging","public exposure","misconfiguration","misconfig","cloud posture","cloud security posture management","cspm","easm","external attack surface management","attack surface","fingerprinting","cpe","recon","subdomain discovery","certificate transparency","crt.sh","spf","dmarc","dkim","email security","email spoofing","phishing","cors","security headers","hsts","soc2","iso27001","hipaa","pci dss","nist"],"author":{"name":"Ala Bouali","email":"ala.bouali.1997@gmail.com"},"license":"SEE LICENSE IN LICENSE.md","_id":"@arcane-spark/ubel-node@0.16.2","maintainers":[{"name":"alabouali","email":"ala.bouali.1997@gmail.com"}],"homepage":"https://github.com/AlaBouali/ubel#readme","bugs":{"url":"https://github.com/AlaBouali/ubel/issues"},"bin":{"ubel-uv":"bin/uv.js","ubel-apt":"bin/apt.js","ubel-bun":"bin/bun.js","ubel-dnf":"bin/dnf.js","ubel-mal":"bin/mal.js","ubel-npm":"bin/npm.js","ubel-pip":"bin/pip.js","ubel-url":"bin/url.js","ubel-yum":"bin/yum.js","ubel-cicd":"bin/cicd.js","ubel-easm":"bin/easm.js","ubel-host":"bin/host.js","ubel-pipx":"bin/pipx.js","ubel-pnpm":"bin/pnpm.js","ubel-sast":"bin/sast.js","ubel-yarn":"bin/yarn.js","ubel-agent":"bin/agent.js","ubel-chunk":"bin/chunk.js","ubel-cloud":"bin/cloud.js","ubel-docker":"bin/docker.js","ubel-domain":"bin/domain.js","ubel-license":"bin/license.js","ubel-secrets":"bin/secrets.js","ubel-composer":"bin/composer.js","ubel-platform":"bin/platform.js"},"dist":{"shasum":"4787951e50dce1315bb6a4f4f42d49922a602f08","tarball":"https://registry.npmjs.org/@arcane-spark/ubel-node/-/ubel-node-0.16.2.tgz","fileCount":256,"integrity":"sha512-iPbNt0PWZiR0+ppEPd92q8uPXpyetLc3mynk3UiSgM+LCgMPAxKaTwPS63PemGmF1OtX+ADzYE9RJVoDJhMfHA==","signatures":[{"sig":"MEQCIFZHPHdMLW1hL+0BxCC5DIc36rclK8qLWwEOoI5vV+MGAiAoiPtSavZ0265pG36jDyMhqVjH4ySkSHDrm795EgI0ag==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIB5jLXnUFcmtHdyCeA2GyyT8SWm7LacUFa9wXbMOsy3uAiEA+CDHbPMHAsa6McF0qXyicrqSqJHfOwt1Y9voxgSFyo0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":3029281},"main":"sca/main.js","type":"module","engines":{"node":">=18.0.0"},"exports":{"./sca":"./sca/main.js","./sast":"./sast/main.js"},"gitHead":"85b3afcab5271f760d5b4d3e56e8b1dfcf670ecd","scripts":{},"_npmUser":{"name":"alabouali","email":"ala.bouali.1997@gmail.com"},"repository":{"url":"git+https://github.com/AlaBouali/ubel.git","type":"git","directory":"node"},"_npmVersion":"10.8.0","description":"Software supply-chain and source-code security for Node.js. SCA: resolves dependencies, scans via OSV.dev and NVD, and annotates findings with heuristic reachability (SBOM/CycloneDX + SARIF reporting). Firewall: gates npm/pnpm/bun installs behind a lockfi","directories":{},"_nodeVersion":"22.16.0","dependencies":{},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ubel-node_0.16.2_1789951780846_0.06232370885604688","host":"s3://npm-registry-packages-npm-production"}},"0.17.0":{"name":"@arcane-spark/ubel-node","version":"0.17.0","keywords":["security","supply-chain","vulnerability","audit","firewall","sbom","osv","nvd","npm","pnpm","bun","dependencies","policy","sca","cve","compliance","scanner","infection","malware","yarn","devsecops","cvss","lockfile","cyclonedx","sast","secrets","secret scanning","credential detection","grc","devops","devsecops","sarif","license","license compliance","backdoor","supply chain","software composition analysis","software supply chain","information security","application security","application security testing","appsec","iac","infrastructure as code","docker","container security","pip","uv","pypi","python","pipx","apt","dnf","yum","linux firewall","cloud security","cloud misconfiguration","cspm","aws","gcp","azure","iam","encryption","audit logging","public exposure","misconfiguration","misconfig","cloud posture","cloud security posture management","cspm","easm","external attack surface management","attack surface","fingerprinting","cpe","recon","subdomain discovery","certificate transparency","crt.sh","spf","dmarc","dkim","email security","email spoofing","phishing","cors","security headers","hsts","soc2","iso27001","hipaa","pci dss","nist"],"author":{"name":"Ala Bouali","email":"ala.bouali.1997@gmail.com"},"license":"SEE LICENSE IN LICENSE.md","_id":"@arcane-spark/ubel-node@0.17.0","maintainers":[{"name":"alabouali","email":"ala.bouali.1997@gmail.com"}],"homepage":"https://github.com/AlaBouali/ubel#readme","bugs":{"url":"https://github.com/AlaBouali/ubel/issues"},"bin":{"ubel-uv":"bin/uv.js","ubel-apt":"bin/apt.js","ubel-bun":"bin/bun.js","ubel-dnf":"bin/dnf.js","ubel-mal":"bin/mal.js","ubel-npm":"bin/npm.js","ubel-pip":"bin/pip.js","ubel-url":"bin/url.js","ubel-yum":"bin/yum.js","ubel-cicd":"bin/cicd.js","ubel-easm":"bin/easm.js","ubel-host":"bin/host.js","ubel-pipx":"bin/pipx.js","ubel-pnpm":"bin/pnpm.js","ubel-sast":"bin/sast.js","ubel-yarn":"bin/yarn.js","ubel-agent":"bin/agent.js","ubel-chunk":"bin/chunk.js","ubel-cloud":"bin/cloud.js","ubel-docker":"bin/docker.js","ubel-domain":"bin/domain.js","ubel-license":"bin/license.js","ubel-secrets":"bin/secrets.js","ubel-composer":"bin/composer.js","ubel-platform":"bin/platform.js"},"dist":{"shasum":"18a9666136b8a23dc733bb3cd0ed1fd6c3af5800","tarball":"https://registry.npmjs.org/@arcane-spark/ubel-node/-/ubel-node-0.17.0.tgz","fileCount":256,"integrity":"sha512-2rWEZVvhp+Eg7iIyaiHJnZ+gI2MgAgz6hHlRmDtkPp/ShkQh3o17C0Un56FkqxkJZrHnFVKGOiODzwvdixEcTA==","signatures":[{"sig":"MEQCIAmK0d0j1Z49Kf0GCK236+Sqk5Cffr1aMItrQ7zNU0zOAiBC+xYbIZAEuCi1H7vWswJ4X4kCwf4z02VF/6IDLdqOsw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQD7q8zyR5ZUtl1ZaZkqksyHLl3es/CbQphV10lxby1c8QIhAK2mTJi7z0e1RtocB1XyTrr+luT0aDEt7akf2lfEqDIa","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":3051749},"main":"sca/main.js","type":"module","engines":{"node":">=18.0.0"},"exports":{"./sca":"./sca/main.js","./sast":"./sast/main.js"},"gitHead":"c4338e42c91531cfeab6ef0e795031b8fc6a82c6","scripts":{},"_npmUser":{"name":"alabouali","email":"ala.bouali.1997@gmail.com"},"repository":{"url":"git+https://github.com/AlaBouali/ubel.git","type":"git","directory":"node"},"_npmVersion":"10.8.0","description":"Software supply-chain and source-code security for Node.js. SCA: resolves dependencies, scans via OSV.dev and NVD, and annotates findings with heuristic reachability (SBOM/CycloneDX + SARIF reporting). Firewall: gates npm/pnpm/bun installs behind a lockfi","directories":{},"_nodeVersion":"22.16.0","dependencies":{},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ubel-node_0.17.0_1790617211473_0.279445815482815","host":"s3://npm-registry-packages-npm-production"}},"0.18.0":{"name":"@arcane-spark/ubel-node","version":"0.18.0","keywords":["security","supply-chain","vulnerability","audit","firewall","sbom","osv","nvd","npm","pnpm","bun","dependencies","policy","sca","cve","compliance","scanner","infection","malware","yarn","devsecops","cvss","lockfile","cyclonedx","sast","secrets","secret scanning","credential detection","grc","devops","devsecops","sarif","license","license compliance","backdoor","supply chain","software composition analysis","software supply chain","information security","application security","application security testing","appsec","iac","infrastructure as code","docker","container security","pip","uv","pypi","python","pipx","apt","dnf","yum","swift","swiftpm","carthage","flutter","dart","pub.dev","linux firewall","cloud security","cloud misconfiguration","cspm","aws","gcp","azure","iam","encryption","audit logging","public exposure","misconfiguration","misconfig","cloud posture","cloud security posture management","cspm","easm","external attack surface management","attack surface","fingerprinting","cpe","recon","subdomain discovery","certificate transparency","crt.sh","spf","dmarc","dkim","email security","email spoofing","phishing","cors","security headers","hsts","soc2","iso27001","hipaa","pci dss","nist"],"author":{"name":"Ala Bouali","email":"ala.bouali.1997@gmail.com"},"license":"SEE LICENSE IN LICENSE.md","_id":"@arcane-spark/ubel-node@0.18.0","maintainers":[{"name":"alabouali","email":"ala.bouali.1997@gmail.com"}],"homepage":"https://github.com/AlaBouali/ubel#readme","bugs":{"url":"https://github.com/AlaBouali/ubel/issues"},"bin":{"ubel-uv":"bin/uv.js","ubel-apt":"bin/apt.js","ubel-bun":"bin/bun.js","ubel-dnf":"bin/dnf.js","ubel-mal":"bin/mal.js","ubel-npm":"bin/npm.js","ubel-pip":"bin/pip.js","ubel-url":"bin/url.js","ubel-yum":"bin/yum.js","ubel-cicd":"bin/cicd.js","ubel-easm":"bin/easm.js","ubel-host":"bin/host.js","ubel-pipx":"bin/pipx.js","ubel-pnpm":"bin/pnpm.js","ubel-sast":"bin/sast.js","ubel-yarn":"bin/yarn.js","ubel-agent":"bin/agent.js","ubel-chunk":"bin/chunk.js","ubel-cloud":"bin/cloud.js","ubel-docker":"bin/docker.js","ubel-domain":"bin/domain.js","ubel-license":"bin/license.js","ubel-secrets":"bin/secrets.js","ubel-composer":"bin/composer.js","ubel-platform":"bin/platform.js"},"dist":{"shasum":"d0f8cb20684f9369411312b974689808b01b02b9","tarball":"https://registry.npmjs.org/@arcane-spark/ubel-node/-/ubel-node-0.18.0.tgz","fileCount":258,"integrity":"sha512-jh6bmTN+6VA79m85jpfwoV224KUCNib0+ZgZklnkdV+CVcNK3KQSYej86meCp3FJe9IGJTQpBLTd01Mj9tEEjA==","signatures":[{"sig":"MEMCHyPZBRQy51lFyQtsi2siVkDMKXHSAKsIpfrc1O7BETgCIBskpfZRnwH3CUkfAVuoyU3m1ad/Q4O4F5xkLwciFdAN","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQCESQ8Nm33yXj3hxMsSCmZKwG+GHHDF48et3X9vD1cEKAIgdR8/wiPxq6EHzB6zU6k/0SFBhEXxjqSmr+P1/crrtxs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":3102142},"main":"sca/main.js","type":"module","engines":{"node":">=18.0.0"},"exports":{"./sca":"./sca/main.js","./sast":"./sast/main.js"},"gitHead":"7fbe2a4604a6905f305300bffddd6c37849fa48e","scripts":{},"_npmUser":{"name":"alabouali","email":"ala.bouali.1997@gmail.com"},"repository":{"url":"git+https://github.com/AlaBouali/ubel.git","type":"git","directory":"node"},"_npmVersion":"10.8.0","description":"Software supply-chain and source-code security for Node.js. SCA: resolves dependencies, scans via OSV.dev and NVD, and annotates findings with heuristic reachability (SBOM/CycloneDX + SARIF reporting). Firewall: gates npm/pnpm/bun installs behind a lockfi","directories":{},"_nodeVersion":"22.16.0","dependencies":{},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ubel-node_0.18.0_1790688359709_0.6428521278986268","host":"s3://npm-registry-packages-npm-production"}},"0.18.1":{"_id":"@arcane-spark/ubel-node@0.18.1","bin":{"ubel-uv":"bin/uv.js","ubel-apt":"bin/apt.js","ubel-bun":"bin/bun.js","ubel-dnf":"bin/dnf.js","ubel-mal":"bin/mal.js","ubel-npm":"bin/npm.js","ubel-pip":"bin/pip.js","ubel-url":"bin/url.js","ubel-yum":"bin/yum.js","ubel-cicd":"bin/cicd.js","ubel-easm":"bin/easm.js","ubel-host":"bin/host.js","ubel-pipx":"bin/pipx.js","ubel-pnpm":"bin/pnpm.js","ubel-sast":"bin/sast.js","ubel-yarn":"bin/yarn.js","ubel-agent":"bin/agent.js","ubel-chunk":"bin/chunk.js","ubel-cloud":"bin/cloud.js","ubel-docker":"bin/docker.js","ubel-domain":"bin/domain.js","ubel-license":"bin/license.js","ubel-secrets":"bin/secrets.js","ubel-composer":"bin/composer.js","ubel-platform":"bin/platform.js"},"bugs":{"url":"https://github.com/AlaBouali/ubel/issues"},"dist":{"shasum":"a52672935ca278bd4a969a4b1e90cb25d6cc5939","tarball":"https://registry.npmjs.org/@arcane-spark/ubel-node/-/ubel-node-0.18.1.tgz","fileCount":258,"integrity":"sha512-61F3qj2j/ZmiyV4HvUYL2/SSk0APAITvgu1LMs/ecv6bX6Mj/oMhMzHCJrrNSaakcSv2a/zemq1Vp4QBsF36Mw==","signatures":[{"sig":"MEUCIBVymn9cC0Dkcvvyy47gq77ZsgLIEvtRrb2sJCuUAW/fAiEAl7o5gfWvbKMFzWWXxljkrpbm/pDyKj+wdVtiWKNcEWk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCID2g2Uq3nWKKrWaOTJJ+mORlksG/cvokNV9ZqIBXb9TYAiEAv+VakPfbEPVZe906ytIdL8Q/X8GYSo8ZJ9AyH2CT1+U="}],"unpackedSize":3116899},"main":"sca/main.js","name":"@arcane-spark/ubel-node","type":"module","author":{"name":"Ala Bouali","email":"ala.bouali.1997@gmail.com"},"engines":{"node":">=18.0.0"},"exports":{"./sca":"./sca/main.js","./sast":"./sast/main.js"},"gitHead":"168840de1c114557b6ecfa48d088dbab17597211","license":"SEE LICENSE IN LICENSE.md","scripts":{},"version":"0.18.1","_npmUser":{"name":"alabouali","email":"ala.bouali.1997@gmail.com"},"homepage":"https://github.com/AlaBouali/ubel#readme","keywords":["security","supply-chain","vulnerability","audit","firewall","sbom","osv","nvd","npm","pnpm","bun","dependencies","policy","sca","cve","compliance","scanner","infection","malware","yarn","devsecops","cvss","lockfile","cyclonedx","sast","secrets","secret scanning","credential detection","grc","devops","devsecops","sarif","license","license compliance","backdoor","supply chain","software composition analysis","software supply chain","information security","application security","application security testing","appsec","iac","infrastructure as code","docker","container security","pip","uv","pypi","python","pipx","apt","dnf","yum","swift","swiftpm","carthage","flutter","dart","pub.dev","linux firewall","cloud security","cloud misconfiguration","cspm","aws","gcp","azure","iam","encryption","audit logging","public exposure","misconfiguration","misconfig","cloud posture","cloud security posture management","cspm","easm","external attack surface management","attack surface","fingerprinting","cpe","recon","subdomain discovery","certificate transparency","crt.sh","spf","dmarc","dkim","email security","email spoofing","phishing","cors","security headers","hsts","soc2","iso27001","hipaa","pci dss","nist"],"repository":{"url":"git+https://github.com/AlaBouali/ubel.git","type":"git","directory":"node"},"_npmVersion":"10.8.0","description":"Software supply-chain and source-code security for Node.js. SCA: resolves dependencies, scans via OSV.dev and NVD, and annotates findings with heuristic reachability (SBOM/CycloneDX + SARIF reporting). Firewall: gates npm/pnpm/bun installs behind a lockfi","directories":{},"maintainers":[{"name":"alabouali","email":"ala.bouali.1997@gmail.com"}],"_nodeVersion":"22.16.0","dependencies":{},"_hasShrinkwrap":false,"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/ubel-node_0.18.1_1790756373904_0.22475930349227458"}}},"time":{"created":"2026-05-04T22:41:11.082Z","modified":"2026-09-30T08:19:34.296Z","0.1.0":"2026-05-04T22:41:11.333Z","0.1.1":"2026-05-05T01:19:21.342Z","0.1.2":"2026-05-06T21:08:16.350Z","0.1.3":"2026-05-07T01:58:13.532Z","0.1.4":"2026-05-07T17:51:37.120Z","0.2.0":"2026-05-11T00:13:09.629Z","0.3.0":"2026-05-21T04:09:15.798Z","0.4.0":"2026-06-27T18:01:46.956Z","0.5.0":"2026-06-27T18:02:52.761Z","0.6.0":"2026-06-27T18:32:03.852Z","0.7.0":"2026-07-24T10:11:01.564Z","0.8.0":"2026-08-01T15:15:09.237Z","0.8.1":"2026-08-01T20:18:26.638Z","0.9.0":"2026-08-01T20:41:28.447Z","0.10.0":"2026-08-05T14:31:35.840Z","0.11.0":"2026-08-13T13:47:22.716Z","0.12.0":"2026-09-08T14:00:30.809Z","0.13.0":"2026-09-12T20:20:17.025Z","0.13.1":"2026-09-12T20:54:30.068Z","0.14.0":"2026-09-18T00:18:12.304Z","0.14.1":"2026-09-18T13:26:19.560Z","0.14.2":"2026-09-19T18:21:25.853Z","0.15.0":"2026-09-19T19:12:03.236Z","0.16.0":"2026-09-20T19:35:37.334Z","0.16.1":"2026-09-20T23:58:47.139Z","0.16.2":"2026-09-21T00:49:40.957Z","0.17.0":"2026-09-28T17:40:11.609Z","0.18.0":"2026-09-29T13:25:59.829Z","0.18.1":"2026-09-30T08:19:34.026Z"},"bugs":{"url":"https://github.com/AlaBouali/ubel/issues"},"author":{"name":"Ala Bouali","email":"ala.bouali.1997@gmail.com"},"license":"SEE LICENSE IN LICENSE.md","homepage":"https://github.com/AlaBouali/ubel#readme","keywords":["security","supply-chain","vulnerability","audit","firewall","sbom","osv","nvd","npm","pnpm","bun","dependencies","policy","sca","cve","compliance","scanner","infection","malware","yarn","devsecops","cvss","lockfile","cyclonedx","sast","secrets","secret scanning","credential detection","grc","devops","devsecops","sarif","license","license compliance","backdoor","supply chain","software composition analysis","software supply chain","information security","application security","application security testing","appsec","iac","infrastructure as code","docker","container security","pip","uv","pypi","python","pipx","apt","dnf","yum","swift","swiftpm","carthage","flutter","dart","pub.dev","linux firewall","cloud security","cloud misconfiguration","cspm","aws","gcp","azure","iam","encryption","audit logging","public exposure","misconfiguration","misconfig","cloud posture","cloud security posture management","cspm","easm","external attack surface management","attack surface","fingerprinting","cpe","recon","subdomain discovery","certificate transparency","crt.sh","spf","dmarc","dkim","email security","email spoofing","phishing","cors","security headers","hsts","soc2","iso27001","hipaa","pci dss","nist"],"repository":{"url":"git+https://github.com/AlaBouali/ubel.git","type":"git","directory":"node"},"description":"Software supply-chain and source-code security for Node.js. SCA: resolves dependencies, scans via OSV.dev and NVD, and annotates findings with heuristic reachability (SBOM/CycloneDX + SARIF reporting). Firewall: gates npm/pnpm/bun installs behind a lockfi","maintainers":[{"name":"alabouali","email":"ala.bouali.1997@gmail.com"}],"readme":"# UBEL — Node.js\r\n\r\n**Software supply-chain and source-code security: dependency scanning, an install-time firewall, and AI-powered source-level scanning ( SAST ) .**\r\n\r\nUBEL is a zero-dependency, source-available application security toolkit. This package (`@arcane-spark/ubel-node`) ships multiple CLIs for dependency-security and source-level scanner:\r\n\r\n- **SCA** — resolves your dependency tree (and, in full-stack mode, other ecosystems present in the repo) and scans it against OSV.dev and NVD **in real time, on every scan** — not from a periodically-synced local database — with heuristic reachability analysis, SBOM (CycloneDX v1.6), and SARIF output. Both endpoints can be pointed at internal mirrors via `UBEL_OSV_ENDPOINT`/`UBEL_NVD_ENDPOINT` for air-gapped deployments (see [sca/README.md](https://github.com/AlaBouali/ubel/blob/main/sca/README.md#environment-variables)). This is the audit/reporting side — `health` mode reads what's already installed.\r\n- **Firewall** — a distinct mode of the same CLI (`check` / `install`) that gates the install itself before anything touches `node_modules`, `pnpm`'s store, `bun`'s install path, or Composer's `vendor/` directory, with atomic lockfile revert on violation and SHA-256 TOCTOU checks between scan and install. The same pull → scan → keep-or-remove pattern also gates **Docker images** (`ubel-docker install <image>`) before you run them. **Also included in this same package:** `ubel-pip`/`ubel-uv`/`ubel-pipx` gate `pip`/`uv` installs and isolated CLI-tool installs behind a dry-run resolution, and `ubel-apt`/`ubel-dnf`/`ubel-yum` (one binary per package manager, same as npm/pnpm/bun) gate `apt`/`dnf`/`yum` installs behind each one's own native dry-run — neither has a lockfile to revert, so a rejected scan simply never runs the real install rather than reverting one.\r\n- **Secrets Detection** — built on Trivy's ported, Apache-2.0-attributed secret-scanning ruleset (see [NOTICE](https://github.com/AlaBouali/ubel/blob/main/sca/vendor/trivy/NOTICE)), extended with UBEL's own rules for vendors Trivy's current upstream doesn't cover (HashiCorp Vault tokens, GCP API keys and OAuth tokens, Anthropic and OpenRouter keys, Stripe restricted keys, Twilio Account/App SIDs, and URL-embedded git credentials, among others). Runs standalone via `ubel-secrets`, or as part of any SCA/firewall scan.\r\n- **License Compliance** — every scanned package's declared license (SPDX id, free text like \"Apache 2.0\", npm's `UNLICENSED` proprietary sentinel, a Python trove classifier, an SPDX `OR`/`AND` expression, or missing entirely) is normalized and checked against the OSI-approved license list, with a derived risk rating (permissive / weak-copyleft / strong-copyleft / proprietary / unknown). Included in every SCA/firewall scan by default — surfaced per-package in the HTML report, as license properties on every SBOM component, and as a dedicated SARIF run. Runs standalone via `ubel-license` — inventory + license classification only, no OSV/NVD vulnerability lookups, no secrets scan.\r\n- **Compliance Framework Mapping** — every finding across SCA (vulnerabilities, secrets), SAST (vulnerability and malicious-code findings), and Cloud (misconfigurations) is mapped onto OWASP Top 10, PCI DSS, HIPAA, SOC 2, ISO/IEC 27001, NIST SP 800-53, GDPR, and CIS Controls v8, via one shared mapping engine so the same underlying risk maps identically regardless of which module found it. Included by default in every scan, with a report-level per-framework/per-control finding-count summary, across JSON, HTML, and SARIF (where the module emits SARIF). Best-effort guidance, not a certified compliance assessment — see the per-module docs for the full framework list and the disclaimer carried in every report.\r\n- **SAST / Malicious-Code Scanner** — a separate module: an LLM-powered pipeline (**scan → verify → taint-trace**) that reads your actual source code, cross-references a structured CWE-mapped vulnerability catalog, and separately screens for intentionally malicious code (backdoors, C2 beacons, supply-chain implants). It also scans IaC, Docker, and Kubernetes manifest files — each as its own dedicated language family, not lumped together.\r\n- **Cloud** — scans your AWS, GCP, and Azure accounts directly via each provider's own read-only API (live account state, not static IaC files) for misconfigurations: public storage/database/network exposure, over-permissive IAM and cluster (AKS/GKE) authorization, missing encryption, and disabled audit logging (CloudTrail/GuardDuty/VPC flow logs). Runs via `ubel-cloud`. See [cloud/README.md](https://github.com/AlaBouali/ubel/blob/main/cloud/README.md).\r\n- **EASM** — passively fingerprints the software exposed on a domain/URL over plain HTTP(S) (server banners, version headers, page markup — no auth, no brute force, no exploitation), checks the result against OSV.dev/NVD/wpvulnerability.net (the same vulnerability-lookup engine the SCA module uses, plus a dedicated WordPress plugin/theme/core lookup), and separately checks every host for a fixed set of common misconfigurations: exposed `.env`/`.git`, WordPress `xmlrpc.php`/user enumeration, TLS/certificate weaknesses, missing/weak security headers and cookie flags, risky HTTP methods (TRACE/PUT/DELETE), CORS misconfiguration, and SPF/DMARC/DKIM email-authentication gaps. Runs via `ubel-url` against hosts you already know, `ubel-domain` to discover a domain's subdomains from Certificate Transparency logs (crt.sh) first — no DNS brute-forcing, no wordlists — and scan all of them in one run, `ubel-host` to connect-scan every port on one host and fingerprint whatever answers HTTP(S), or `ubel-easm` to combine both — discover a domain's subdomains, resolve them to distinct IPs, port-scan each, and fingerprint the combined result. **Authorized use only — see [easm/README.md](https://github.com/AlaBouali/ubel/blob/main/easm/README.md).**\r\n\r\nEverything runs on your own infrastructure: no source code egress, no credentials required beyond your chosen LLM provider's API key (SAST only), no telemetry.\r\n\r\n---\r\n\r\n## Install\r\n\r\n```bash\r\nnpm install -g @arcane-spark/ubel-node\r\n```\r\n\r\nThis installs the binaries for the SCA/firewall CLI, the SAST module, the cloud scanner, and the EASM scanner:\r\n\r\n| Binary | Covers | What it does |\r\n|---|---|---|\r\n| `ubel-npm` / `ubel-pnpm` / `ubel-bun` | SCA + Firewall | Same binary, mode-dependent: `health` = SCA scan of installed deps; `check`/`install` = firewall gate on a lockfile dry-run |\r\n| `ubel-composer` | SCA + Firewall | `health` = SCA scan of `vendor/`/`composer.lock`; `check`/`install` = firewall gate on a `composer require`/`update --no-install --no-scripts` dry-run, same lockfile-backed shape as npm/pnpm/bun |\r\n| `ubel-pip` / `ubel-pipx` | SCA + Firewall | `health` = SCA scan of a venv's installed packages; `check`/`install` = firewall gate on a `pip install --dry-run` resolution. `ubel-pipx` additionally installs CLI tools into isolated, managed per-tool venvs with a global shim, reducing blast radius the way `pipx` itself does |\r\n| `ubel-uv` | SCA + Firewall | Same `health`/`check`/`install` split as `ubel-pip`, but targeting a uv-native venv (`uv init --bare` + `uv venv`, not a stdlib one) — the real install always still runs as `uv pip install -r <generated, exact-pinned file>`, same as pip; dry-run uses `uv pip install --dry-run` internally, which (unlike pip's JSON report) yields no dependency-graph data — see the Python section below. A real `install` on either engine also syncs any existing `requirements.txt`/`pyproject.toml` to the now-installed versions |\r\n| `ubel-apt` / `ubel-dnf` / `ubel-yum` | SCA + Firewall | Same `health`/`check`/`install` split, one binary per native package manager (no auto-detection between them, same as npm/pnpm/bun). Reports and policy live under `~/.ubel/local` so routine use never needs `sudo` — only the real package-manager install does |\r\n| `ubel-docker` | SCA + Firewall | Scans a container image without running it; `install` mode pulls, scans, and removes the image on a policy violation |\r\n| `ubel-secrets` | Secrets | Standalone secrets-only scan of the target directory — no dependency resolution, no LLM calls |\r\n| `ubel-license` | SCA | Standalone inventory + license-compliance scan — no vulnerability lookups (OSV/NVD), no secrets scan |\r\n| `ubel-agent` | SCA | AI-agent workspace scan (OS, runtimes, tools, dependencies) |\r\n| `ubel-cicd` | SCA | Post-install CI/CD scan of the final built workspace (OS, runtimes, tools, dependencies) |\r\n| `ubel-platform` | SCA | Host platform scan (OS, runtimes, tools) |\r\n| `ubel-sast` | SAST | Static analysis for accidental vulnerabilities (injection, XSS, insecure deserialization, hardcoded secrets, …) |\r\n| `ubel-mal` | SAST | Malicious-code scan for intentional backdoors, C2 implants, exfiltration, persistence |\r\n| `ubel-chunk` | SAST | Free, LLM-cost-free utility to preview how a codebase will be chunked |\r\n| `ubel-cloud` | Cloud | Live AWS/GCP/Azure account scan via each provider's own API for misconfigurations — public exposure, IAM, encryption, audit logging — not a static IaC/manifest scan |\r\n| `ubel-url` | EASM | Passive HTTP(S) fingerprinting of a domain/URL + OSV/NVD/wpvulnerability.net vulnerability lookup and misconfiguration checks on what it finds — **authorized use only, against infrastructure you own** |\r\n| `ubel-domain` | EASM | Same as `ubel-url`, but discovers its own target list first — enumerates a domain's subdomains via Certificate Transparency logs (crt.sh), then runs the same fingerprinting/vulnerability/misconfiguration scan against all of them — **authorized use only, against infrastructure you own** |\r\n| `ubel-host` | EASM | Connect-scans every port in a range (default 1-30000) on one host, probes whatever accepts a connection for HTTP(S), then runs the same fingerprinting/vulnerability/misconfiguration scan `ubel-url` does against whatever answered — **authorized use only, against infrastructure you own** |\r\n| `ubel-easm` | EASM | Combines `ubel-domain`'s discovery with `ubel-host`'s port sweep — discovers a domain's subdomains, resolves them to distinct IPs, port-scans every IP, and fingerprints the merged IP:port targets plus the subdomains themselves by name — the most invasive EASM entry point; see the \"Shared IPs\" warning in `easm/README.md` — **authorized use only, against infrastructure you own** |\r\n\r\n`ubel-pip`/`ubel-uv`/`ubel-pipx` additionally need a `python3`/`python` interpreter on `PATH` (to create their venv); Node.js itself can't provision one. `ubel-uv` additionally needs the `uv` binary itself on `PATH`, separate from Python — same one-binary-per-tool requirement as `ubel-pnpm` needing `pnpm`. `ubel-composer` additionally needs the `composer` binary itself on `PATH`, same one-binary-per-tool requirement.\r\n\r\nNode.js `>=18.0.0` required.\r\n\r\n---\r\n\r\n## SCA — Dependency Vulnerability Scanning\r\n\r\nResolves dependencies (with PURL generation), scans them against OSV.dev and NVD, and annotates each finding with a heuristic **reachability** verdict (package type, scope, dependency depth, attack vector, and optional source-level import-scan confirmation). Malicious-package advisories (`MAL-*`) are always flagged. Output: JSON, HTML, CycloneDX v1.6 SBOM, and SARIF 2.1.0 reports.\r\n\r\n```bash\r\n# Audit the currently installed dependency graph — no install, no lockfile mutation\r\nubel-npm health\r\nubel-pnpm health\r\nubel-bun health\r\nubel-composer health\r\n```\r\n\r\n`health` mode also supports full-stack monorepo scanning (Python, PHP, Rust, Go, .NET, Java, Ruby, Swift, Flutter/Dart alongside Node) and host/platform scanning (Linux package managers, Windows registry) when invoked programmatically.\r\n\r\n**yarn** is supported in `health` mode only — it can't do a lockfile-only dry-run, so it has no firewall coverage below.\r\n\r\n## Firewall — Install-Time Gate\r\n\r\nA distinct mode of the same `ubel-npm` / `ubel-pnpm` / `ubel-bun` binaries: before any real install, a lockfile-only dry-run (`--package-lock-only` / `--lockfile-only`) resolves the candidate tree without touching `node_modules`, scans it, and either proceeds or reverts the lockfile from its on-disk backup. Pre/post-install scripts are always blocked (`--ignore-scripts`) during this phase. A SHA-256 check re-verifies the lockfile and `package.json` immediately before the real install, closing the TOCTOU window between scan and install.\r\n\r\nThe same block-before-you-touch-it pattern applies to `ubel-docker`: `install` mode pulls the image, extracts its filesystem without ever running it (`docker create` + in-process tar extraction, no shell `tar`, no `ENTRYPOINT`/`CMD` execution), scans it, and removes the image again if policy blocks it.\r\n\r\n`ubel-composer` extends the same lockfile-backed pattern npm/pnpm/bun use to PHP: `composer require`/`update --no-install --no-scripts` (Composer's own equivalent of `--package-lock-only`) resolves the candidate tree and writes a candidate `composer.lock`/`composer.json` without touching `vendor/`, UBEL scans that candidate, and either proceeds via `composer install --no-scripts` or reverts both files from their on-disk backup — the same SHA-256 TOCTOU check and atomic revert as npm/pnpm/bun, just against Composer's own files. Unlike pip's dry-run below, this has no sdist-style caveat: resolving a Composer dependency graph never runs a package's own code, since build/lifecycle scripts only fire on a real `composer install`/`update`, which is exactly why `--no-scripts` covers both the dry-run and the real install.\r\n\r\n`ubel-pip`/`ubel-uv`/`ubel-pipx` extend the same before-you-touch-it approach to Python: `pip install --dry-run --report` (pip) or `uv pip install --dry-run` (uv) resolves the candidate set — including transitive dependencies — without installing anything, UBEL scans that resolution, and only then runs the real install (`pip install -r` / `uv pip install -r` against the same generated, exact-pinned file either way). A successful real install additionally syncs any `requirements.txt`/`pyproject.toml` already sitting in the project directory to the versions that actually got installed — see the Python section further down for exactly what that does and doesn't touch. There's no lockfile here, so there's nothing to revert — a blocked scan just means the real install never runs. One caveat worth being upfront about, and it applies to both installers equally since it's inherent to how Python packaging resolution works: resolving a package's metadata can still need to build an sdist when no pre-built wheel is available, and building an sdist can execute arbitrary `setup.py`/build-backend code — a wheel-only install has no such gap, but a source-only package does carry it. `ubel-apt`/`ubel-dnf`/`ubel-yum` mirror this for Linux host packages — three separate binaries, each bound to exactly one package manager's own native dry-run (`apt-get -s`, `dnf --assumeno`, `yum --assumeno` respectively, no auto-detection between them); their reports and policy live under `~/.ubel/local` so ordinary use never needs `sudo` — only the real install does.\r\n\r\n```bash\r\n\r\n# examples\r\n\r\n# Dry-run only — scan and exit, nothing installed\r\nubel-npm check lodash express\r\n\r\n# Scan-gated real install — proceeds only if policy allows\r\nubel-npm install lodash@4.17.21\r\n\r\n# install current project\r\nubel-pnpm install\r\n\r\n# check the current project\r\n\r\nubel-bun check\r\n\r\n# pull, scan, and keep or remove a Docker image based on policy\r\nubel-docker install node:20-alpine\r\n\r\n# PHP: dry-run scan, then a scan-gated real install\r\nubel-composer check monolog/monolog\r\nubel-composer install monolog/monolog:^3.0\r\nubel-composer install                  # no args → resolves from existing composer.lock\r\n\r\n# Python: dry-run scan, then a scan-gated real install into ./venv\r\nubel-pip check requests==2.31.0\r\nubel-pip install requests==2.31.0\r\nubel-pip install                       # no args → falls back to ./requirements.txt, then ./pyproject.toml\r\n\r\n# Same, driven by uv instead of pip\r\nubel-uv check requests==2.31.0\r\nubel-uv install requests==2.31.0\r\n\r\n# Python CLI tool: scan-gated install into an isolated venv + global shim\r\nubel-pipx install black\r\n\r\n# Linux packages: dry-run scan, then a scan-gated `sudo apt install`\r\nubel-apt check curl\r\nubel-apt install curl\r\n# (ubel-dnf / ubel-yum work the same way, against dnf/yum instead)\r\n```\r\n\r\nPolicy (severity threshold, unknown-severity blocking) is configurable via `ubel-npm threshold <level>` and `ubel-npm block-unknown <bool>` (same subcommands under `ubel-composer`/`ubel-pip`/`ubel-uv`/`ubel-pipx`/`ubel-apt`/`ubel-dnf`/`ubel-yum`); malicious-package advisories are always blocked regardless of policy. License-risk policy (`license-risk`, `license-block-unknown`) is npm-family-only (npm/pnpm/bun/composer) — it isn't exposed as a subcommand on `ubel-pip`/`ubel-uv`/`ubel-pipx`/`ubel-apt`/`ubel-dnf`/`ubel-yum`, matching those CLIs' narrower mode set.\r\n\r\n**Exit codes:** `check` and `install` exit `0` if policy passes, `1` if policy blocks or the scan itself fails — a failed scan is never treated as a pass.\r\n\r\n**Full documentation — every mode, policy config, reachability decision ladder, and programmatic API:**\r\n[**sca/README.md**](https://github.com/AlaBouali/ubel/blob/main/sca/README.md)\r\n\r\n---\r\n\r\n## Fixed-Configuration Scan CLIs\r\n\r\n`ubel-agent`, `ubel-cicd`, and `ubel-platform` wrap the same `health`-mode scan engine as `ubel-npm health`, each with a fixed option set for one deployment context — no `<engine> <mode>` arguments, just an optional target path. All three print the full JSON report to stdout and exit `1` on a policy block.\r\n\r\n```bash\r\n# AI-agent sandbox workspace — OS packages + every app ecosystem present\r\nubel-agent /path/to/agent/workspace\r\n\r\n# Post-build CI/CD scan of the final built workspace\r\nubel-cicd /path/to/build/output\r\n\r\n# Host/developer-machine scan — OS packages and dev tools/runtimes only,\r\n# no application dependency resolution. Defaults to the home directory.\r\nubel-platform\r\n```\r\n\r\n**Full documentation — exact flags per binary and how they differ from `ubel-secrets`/`ubel-license`:**\r\n[**sca/README.md#fixed-configuration-scan-clis**](https://github.com/AlaBouali/ubel/blob/main/sca/README.md#fixed-configuration-scan-clis)\r\n\r\n---\r\n\r\n## Secrets Detection\r\n\r\nBuilt on Trivy's ported secret-scanning ruleset (Apache-2.0, attributed in [`sca/vendor/trivy/NOTICE`](https://github.com/AlaBouali/ubel/blob/main/sca/vendor/trivy/NOTICE)), extended with rules for vendors not yet covered by Trivy's current upstream ruleset: HashiCorp Vault tokens, Google Cloud API keys and OAuth tokens, Anthropic and OpenRouter API keys, Firebase tokens, Stripe restricted keys, Twilio Account/App SIDs, Square and Braintree credentials, and URL-embedded git credentials. Match previews in every report are redacted — the raw secret value is never written to disk.\r\n\r\n```bash\r\n# Standalone secrets-only scan — no dependency resolution, no LLM calls\r\nubel-secrets /path/to/project\r\n```\r\n\r\nSecrets findings are also included in every SCA/firewall scan by default, surfaced in a dedicated tab in the HTML report and as a schema-correct extension on both the SBOM (a `ubel:secrets` property, since CycloneDX's root schema doesn't permit arbitrary top-level keys) and the SARIF output (its own `run`, separate from the dependency-vulnerability run).\r\n\r\n---\r\n\r\n## License Compliance\r\n\r\nEvery scanned package's declared license — whatever form it arrives in (an SPDX id, free text like \"Apache 2.0\", npm's `UNLICENSED` proprietary sentinel, a Python trove classifier, an `OR`/`AND` SPDX expression, or missing entirely) — is normalized into a canonical SPDX identifier, checked against the OSI-approved license list, and assigned a risk rating (`low` / `medium` / `high` / `unknown`) based on license category (permissive, weak-copyleft, strong-copyleft, proprietary, public-domain, unrecognized). Included in every SCA/firewall scan by default.\r\n\r\n```bash\r\n# Standalone inventory + license scan — resolves dependencies (full-stack,\r\n# every ecosystem present in the repo) and classifies licenses only; no\r\n# OSV/NVD calls, no secrets scan. Same JSON, HTML, CycloneDX SBOM, and\r\n# SARIF 2.1.0 outputs as any other SCA scan.\r\nubel-license /path/to/project\r\n```\r\n\r\nSurfaced per-package in the HTML report's inventory table and detail view, as `license.osi_approved` / `license.risk` / `license.category` properties on every SBOM component, and as its own SARIF run (`ubel-license-compliance`) that flags any non-OSI-approved or high-risk license as a finding.\r\n\r\n**Full documentation:** [sca/README.md#license-compliance](https://github.com/AlaBouali/ubel/blob/main/sca/README.md#license-compliance)\r\n\r\n---\r\n\r\n## Compliance Framework Mapping\r\n\r\nEvery finding produced anywhere in UBEL — SCA vulnerabilities and secrets, SAST vulnerability and malicious-code findings, and Cloud misconfigurations — is mapped onto industry compliance/security frameworks by default, no separate flag needed. All three modules share one mapping engine (`sca/compliance_mappings.js`): a finding is assigned one or more internal risk categories (e.g. `injection`, `public_exposure`, `vulnerable_components`), and each category carries a fixed list of framework control references, so the same underlying risk maps identically whether it was found by the dependency scanner, the AI SAST pipeline, or the cloud scanner.\r\n\r\n**Frameworks:** OWASP Top 10 (2021), PCI DSS v4.0, HIPAA Security Rule, SOC 2 (Trust Services Criteria), ISO/IEC 27001:2022 (Annex A), NIST SP 800-53 Rev. 5, GDPR, and CIS Controls v8.\r\n\r\nEvery finding gets a `compliance` object (categories + per-framework control list); every report gets a top-level `compliance_summary` aggregating all findings into per-framework/per-control finding counts. Surfaced in a dedicated Compliance tab in every module's HTML report, in the JSON report's `compliance`/`compliance_summary` fields, and — for SCA and SAST, which emit SARIF — as `compliance`/`compliance_categories`/`compliance_frameworks` properties on SARIF rules and results.\r\n\r\n**This is best-effort guidance, not a certified compliance assessment** — control identifiers are the stable, publicly documented ones for each framework, but framework text, versioning, and applicable scope can change and depend on your own environment. Every report carries this disclaimer verbatim in `compliance_summary.disclaimer`.\r\n\r\n**Full documentation:** [sca/README.md#compliance-framework-mapping](https://github.com/AlaBouali/ubel/blob/main/sca/README.md#compliance-framework-mapping) (canonical framework/category reference) · [sast/README.md#compliance-framework-mapping](https://github.com/AlaBouali/ubel/blob/main/sast/README.md#compliance-framework-mapping) · [cloud/README.md#compliance-framework-mapping](https://github.com/AlaBouali/ubel/blob/main/cloud/README.md#compliance-framework-mapping)\r\n\r\n---\r\n\r\n## SAST — AI-Powered Static Analysis & Malicious Code Scanner\r\n\r\nChunks your codebase into semantically-bounded units (11 language families, including Docker, IaC, and Kubernetes manifests as their own dedicated families) and runs a three-pass LLM pipeline — **scan → verify → taint trace** — cross-referenced against a 59-class CWE-mapped vulnerability catalog. A fully separate 15-class malicious-code catalog covers intentionally planted backdoors and implants; that scan (`ubel-mal`) stops after **scan → verify**, since reachability isn't the relevant question for code that's itself the payload. Outputs JSON, interactive HTML, and SARIF 2.1.0 reports, ready for CI/CD gating.\r\n\r\n```bash\r\n# Vulnerability scan\r\nubel-sast /path/to/project\r\n\r\n# Malicious-code / backdoor scan\r\nubel-mal /path/to/project\r\n\r\n# Free preview of how a codebase will be chunked, no LLM calls\r\nubel-chunk /path/to/project\r\n```\r\n\r\nSupports OpenRouter, OpenAI, Anthropic, Gemini, DeepSeek, NVIDIA, local/Docker-hosted (Ollama-compatible), and fully custom endpoints — selectable per run, no code changes.\r\n\r\n**Exit codes:** governed by `--fail-on`, which only changes the process exit code — reports on disk always contain every finding regardless of this flag.\r\n- `ubel-sast` (`analyze`): `any` *(default)* fails on any finding, including unresolved ones; `valid` fails only on findings verified `is_valid: true`; `exploitable` fails only on findings taint-traced `exploitable: true`.\r\n- `ubel-mal` (`malware`): `any` *(default)* fails on any finding, including unresolved ones; `confirmed` fails only on findings verified `is_valid: true` — an unresolved finding still fails the build, since \"couldn't determine\" is never treated as clean.\r\n\r\n**Full documentation — pipeline mechanics, every flag, token-cost breakdown, and CI examples:**\r\n[**sast/README.md**](https://github.com/AlaBouali/ubel/blob/main/sast/README.md)\r\n\r\n---\r\n\r\n## Cloud — AWS / GCP / Azure Misconfiguration Scanning\r\n\r\nScans your AWS, GCP, and Azure accounts directly via each provider's own read-only API — live account state, not a static IaC/manifest scan, and nothing is deployed or modified. Covers public storage/database/network exposure (S3/GCS/Storage buckets, RDS/Cloud SQL/Azure SQL, security groups/NSGs/firewall rules open to the internet), IAM posture (overly permissive policies, missing MFA, stale access keys, permissive trust policies), Kubernetes cluster authorization (GKE/AKS control-plane exposure, RBAC/ABAC, legacy auth), missing encryption (EBS, RDS, CloudTrail, storage accounts), and disabled audit logging (CloudTrail, GuardDuty, VPC flow logs). Credentials are only ever used for that run — nothing stored or reused, same model as SAST's LLM credentials.\r\n\r\n```bash\r\n# Scan whichever providers you have credentials for (default: aws,gcp,azure)\r\nubel-cloud\r\n\r\n# Scan a specific provider only\r\nubel-cloud --provider aws\r\n\r\n# Explicit AWS region override — skips DescribeRegions auto-discovery\r\nubel-cloud --provider aws --regions us-east-1,eu-west-1\r\n```\r\n\r\nOutputs JSON and HTML (no SARIF, no SBOM — this isn't a dependency scan). **Exit codes:** governed by `--fail-on` (default `critical`), same severity-threshold/count syntax as the rest of UBEL — reports on disk always contain every finding regardless of this flag.\r\n\r\n**Full documentation — every check, per-provider credential setup, and all flags:**\r\n[**cloud/README.md**](https://github.com/AlaBouali/ubel/blob/main/cloud/README.md)\r\n\r\n---\r\n\r\n## EASM — External Attack Surface Fingerprinting\r\n\r\n> **⚠ Authorized use only.** `ubel-url` sends live, unauthenticated requests to\r\n> every target you give it and discloses what it fingerprints to OSV.dev/NVD/\r\n> wpvulnerability.net. `ubel-domain` does the same, but discovers its own\r\n> target list from Certificate Transparency logs first — so it can end up\r\n> scanning hosts you didn't explicitly name. `ubel-host` goes further: it\r\n> connect-scans every port in a range (1-30000 by default) on one host and\r\n> fingerprints whatever answers HTTP(S) — a live port sweep, not just a\r\n> fingerprint request. `ubel-easm` combines both — it discovers a domain's\r\n> subdomains, resolves each to an IP, then runs `ubel-host`'s full port\r\n> sweep against every distinct IP behind the domain, the most invasive of\r\n> the four and the most likely to reach infrastructure you didn't intend to\r\n> touch (shared hosting, a CDN edge IP — see the \"Shared IPs\" note in\r\n> `easm/README.md`). Only ever run any of these four against infrastructure\r\n> you own or have explicit, documented authorization to test — the same\r\n> own-infrastructure-only rule every other UBEL module already holds you to.\r\n> See [easm/README.md](https://github.com/AlaBouali/ubel/blob/main/easm/README.md)\r\n> for the full notice.\r\n\r\nPassively fingerprints the software exposed on a domain/URL over plain\r\nHTTP(S) — server banners, version headers, page markup, a small set of\r\nwell-known paths — turns what it finds into candidate CPE identifiers, and\r\nfeeds those through the exact same OSV.dev/NVD/wpvulnerability.net\r\nvulnerability-lookup engine the SCA module uses (wpvulnerability.net for\r\nWordPress plugins/themes/core specifically, which NVD's CPE dictionary\r\nmostly misses). No authentication, no brute forcing, no exploitation — just\r\nunauthenticated GETs and a lookup against public vulnerability data.\r\n\r\n`ubel-domain` runs the identical scan, with the target list discovered for\r\nyou first:\r\n\r\n```\r\ndomain  →  crt.sh subdomain discovery  →  fingerprint every host\r\n        →  group techs by name+version (with the host list for each)\r\n        →  vulnerability lookup + misconfiguration checks  →  one report\r\n```\r\n\r\nGive it a root domain and it enumerates every subdomain a public CA has\r\nlogged a certificate for (via [crt.sh](https://crt.sh)) — passive discovery\r\nonly, no DNS brute-forcing, no zone-transfer attempts — then fingerprints\r\nall of them in one run through the same engine `ubel-url` uses, so a\r\ntechnology found on forty subdomains is one inventory row with a forty-host\r\nlist, not forty near-identical rows. `--list-only` prints that discovered\r\nlist without sending a single request to any of those hosts, so you can\r\nreview and trim it (`--exclude`, or add hosts crt.sh missed with\r\n`--include`) before authorizing the real scan.\r\n\r\n`ubel-host` adds a step *before* fingerprinting instead of before discovery\r\n— give it one host, and it connect-scans every port in `--ports` (default\r\n`1-30000`), probes whatever accepts a connection for HTTP(S), and hands only\r\nthe HTTP(S)-speaking ports to the same fingerprint/lookup engine `ubel-url`\r\nuses, so you don't need to already know which port a target's web app or\r\nadmin panel lives on. This is genuinely active reconnaissance, not passive\r\nfingerprinting — see the warning above.\r\n\r\n`ubel-easm` is `ubel-domain`'s discovery and `ubel-host`'s port sweep\r\ntogether across a whole domain: crt.sh discovery → resolve every subdomain\r\nto an IP → collapse to the **distinct** IPs actually behind the domain\r\n(several subdomains commonly share one) → port-scan and HTTP(S)-probe each\r\nof those IPs → fingerprint the merged IP:port targets **and** the\r\ndiscovered subdomains by name (a bare-IP request has no Host header/SNI, so\r\nit can't see a name-based virtual host; controlled by `--subdomain-ports`).\r\nA component seen on five IPs behind the domain is still one inventory item,\r\nthe same name+version dedup `ubel-domain` gets across subdomains.\r\n\r\nEvery host is also checked, automatically, for a fixed set of common\r\nmisconfigurations, independent of the CVE lookup above: an exposed\r\n`.env`/`.git`, exposed `phpinfo()` output, TLS/certificate weaknesses\r\n(expiry, trust, hostname mismatch, weak/legacy protocol and cipher support),\r\nmissing/weak security headers and cookie flags (HSTS, CSP, clickjacking\r\nprotection, `X-Content-Type-Options`, `Referrer-Policy`,\r\n`Permissions-Policy`, `Secure`/`HttpOnly`/`SameSite` on any `Set-Cookie`),\r\nrisky HTTP methods (`PUT`/`DELETE`/`TRACE`/`CONNECT` advertised, plus an\r\nactual Cross-Site Tracing probe), CORS misconfiguration (arbitrary-Origin\r\nreflection, a wildcard paired with credentials, the `null` Origin), SPF/\r\nDMARC/DKIM email-authentication gaps, and — on hosts already identified as\r\nWordPress — a reachable `xmlrpc.php` and unauthenticated user enumeration.\r\nThis runs the same way across all four entry points.\r\n\r\nIt's a deliberate subset of an SCA report: no license compliance (no\r\nmanifest to read one off of), no dependency sequences/graph (nothing here\r\nis resolved from a lockfile), no reachability analysis (no source code to\r\ntrace), and no SBOM/SARIF — JSON and HTML only. CVSS scoring, fix-version\r\nrecommendations, and the same compliance framework mapping every other\r\nmodule uses are all still included. Every detected component is reported\r\nwith `scopes: [\"prod\"]` — anything fingerprinted over the network is, by\r\ndefinition, already running.\r\n\r\n```bash\r\n# One domain, safety guard on by default (skips private/self-IP targets)\r\nubel-url example.com\r\n\r\n# Several targets in one run, one report\r\nubel-url a.example.com b.example.com --fail-on high\r\n\r\n# A lab/localhost target you own\r\nubel-url localhost:8080 --allow-private\r\n\r\n# See what a domain-wide sweep would touch, without touching anything\r\nubel-domain your-company.example --list-only\r\n\r\n# Discover every subdomain of a domain you own, then scan them all\r\nubel-domain your-company.example --fail-on high\r\n\r\n# See what ports are open on a host you own, without fingerprinting anything\r\nubel-host app.your-company.example --list-only\r\n\r\n# Port-scan and fingerprint a host you own, well-known ports only\r\nubel-host app.your-company.example --ports 1-1024 --fail-on high\r\n\r\n# Review the IP grouping a combined sweep would touch, before authorizing it\r\nubel-easm your-company.example --list-only\r\n\r\n# Combined discovery + per-IP port sweep of a domain you own\r\nubel-easm your-company.example --fail-on high\r\n```\r\n\r\nOutputs JSON and HTML only. **Exit codes:** governed by `--fail-on` (default\r\n`critical`), same severity-threshold/count syntax as the rest of UBEL —\r\nreports on disk always contain every finding (vulnerabilities and\r\nmisconfigurations alike) regardless of this flag; note that `--fail-on`\r\nitself currently gates on vulnerabilities/infections only, not on\r\nmisconfiguration findings.\r\n\r\n**Full documentation — the responsible-use notice, safety guard, every\r\n`ubel-host`/`ubel-easm` flag, the \"Shared IPs\" warning, and the full\r\nmisconfiguration-check list:**\r\n[**easm/README.md**](https://github.com/AlaBouali/ubel/blob/main/easm/README.md)\r\n\r\n---\r\n\r\n## CI/CD Integration\r\n\r\nAll binaries exit non-zero on findings that clear their respective gate, so any of them fit natively into a CI runner.\r\n\r\n### GitHub Actions — using the packaged action\r\n\r\n[`action.yml`](https://github.com/AlaBouali/ubel/blob/main/action.yml) wraps `npx @arcane-spark/ubel-node@<version>` as a composite action, behind an explicit `command` allow-list validated against UBEL's actual registered `package.json` bin names — so it can never construct or execute a binary name that isn't one of ours, regardless of what a caller passes. `command`, `version`, and `args` are step inputs referenced as shell variables (`$COMMAND`/`$ARGS`), never interpolated directly into the script with `${{ }}`, closing off GitHub's documented script-injection risk for composite actions.\r\n\r\n```yaml\r\n- uses: AlaBouali/ubel@<commit-sha>   # pin to a commit SHA, not a mutable tag\r\n  with:\r\n    command: npm\r\n    version: 0.8.0\r\n    args: check\r\n\r\n- uses: AlaBouali/ubel@<commit-sha>\r\n  with:\r\n    command: npm                      # `command` selects the bin; the mode (check/install/health) goes in `args`\r\n    version: 0.8.0\r\n    args: install\r\n\r\n- uses: AlaBouali/ubel@<commit-sha>\r\n  with:\r\n    command: sast\r\n    args: --fail-on exploitable\r\n\r\n- uses: AlaBouali/ubel@<commit-sha>\r\n  with:\r\n    command: mal\r\n    args: --fail-on confirmed\r\n\r\n- uses: AlaBouali/ubel@<commit-sha>\r\n  with:\r\n    command: license                  # inventory + license compliance only — no OSV/NVD calls, no secrets scan\r\n\r\n- uses: AlaBouali/ubel@<commit-sha>\r\n  with:\r\n    command: cloud\r\n    args: --provider aws,gcp,azure --fail-on high\r\n\r\n- uses: AlaBouali/ubel@<commit-sha>\r\n  with:\r\n    command: url                      # EASM — only ever point `args` at infrastructure you own, see easm/README.md\r\n    args: staging.your-own-domain.example --fail-on high\r\n\r\n- uses: AlaBouali/ubel@<commit-sha>\r\n  with:\r\n    command: pip\r\n    args: install                     # scan-gated `pip install`, resolved from ./requirements.txt\r\n\r\n- uses: AlaBouali/ubel@<commit-sha>\r\n  with:\r\n    command: composer\r\n    args: install                     # scan-gated `composer install --no-scripts`, resolved from composer.lock\r\n\r\n- uses: AlaBouali/ubel@<commit-sha>\r\n  with:\r\n    command: apt                      # dnf/yum work the same way, as their own `command` values\r\n    args: check curl\r\n```\r\n\r\n`command` must be one of: `sast`, `mal`, `chunk`, `cicd`, `agent`, `platform`, `secrets`, `license`, `cloud`, `url`, `npm`, `pnpm`, `bun`, `yarn`, `composer`, `docker`, `pip`, `pipx`, `uv`, `apt`, `dnf`, `yum` — anything else fails the step before `npx` ever runs. `ubel-domain`, `ubel-host`, and `ubel-easm` aren't in this allow-list yet, so a domain-wide sweep, a port scan, or a combined sweep isn't available through the packaged action today — call the binary directly instead (see below).\r\n\r\n### Calling the binaries directly\r\n\r\nEquivalent, for self-hosted runners, non-GitHub CI, or a Dockerfile:\r\n\r\n```yaml\r\n# GitHub Actions\r\n- name: UBEL dependency scan (SCA)\r\n  run: ubel-npm check\r\n\r\n- name: UBEL firewall-gated install\r\n  run: ubel-npm install\r\n\r\n- name: UBEL PHP firewall-gated install\r\n  run: ubel-composer install\r\n\r\n- name: UBEL SAST scan\r\n  run: ubel-sast --fail-on exploitable\r\n\r\n- name: UBEL malicious-code scan\r\n  run: ubel-mal --fail-on confirmed\r\n\r\n- name: UBEL license compliance scan\r\n  run: ubel-license .\r\n\r\n- name: UBEL cloud misconfiguration scan\r\n  run: ubel-cloud --fail-on high\r\n\r\n- name: UBEL external attack surface scan (only against infra you own — see easm/README.md)\r\n  run: ubel-url staging.your-own-domain.example --fail-on high\r\n\r\n- name: UBEL domain-wide attack surface sweep (discovers subdomains first — only against a domain you own)\r\n  run: ubel-domain your-own-domain.example --fail-on high\r\n\r\n- name: UBEL port scan + fingerprint (connect-scans 1-1024, only against a host you own)\r\n  run: ubel-host staging.your-own-domain.example --ports 1-1024 --fail-on high\r\n\r\n- name: UBEL combined discovery + per-IP port sweep (most invasive EASM entry point — only against a domain you own, review with --list-only first)\r\n  run: ubel-easm your-own-domain.example --fail-on high\r\n```\r\n\r\n```dockerfile\r\n# Dockerfile\r\nRUN ubel-npm install\r\nRUN ubel-composer install\r\nRUN ubel-sast --fail-on valid .\r\n```\r\n---\r\n# UBEL — Capability Reference by Ecosystem, Language, and OS\r\n\r\nThis document details exactly what UBEL does — and doesn't do — for every\r\necosystem it supports, across five capability axes:\r\n\r\n- **SCA** — dependency inventory + vulnerability matching (OSV/NVD)\r\n- **Firewall** — pre-install/pre-deploy blocking, not just after-the-fact reporting\r\n- **SAST** — LLM-driven source/config vulnerability scanning\r\n- **Malware SAST** — LLM-driven detection of intentionally malicious code\r\n- **Secrets** — hardcoded credential detection\r\n- **License compliance** — SPDX normalization + OSI/risk classification\r\n- **Compliant outputs** — SARIF, CycloneDX SBOM, JSON, HTML\r\n\r\nA quick note before the detail: **Firewall and SCA are not the same capability\r\neverywhere.** SCA (health scanning) works on anything UBEL can resolve a\r\ndependency tree for. Firewall (blocking a bad install *before* it lands)\r\nonly exists where a package manager supports some form of dry-run\r\nresolution with no (or, for pip/uv, no *typical*) side effects — today\r\nthat's **npm, pnpm, bun, and Docker images** via a true lockfile-only\r\ndry-run, **PHP (Composer)** via the same lockfile-backed mechanism\r\n(`composer require`/`update --no-install --no-scripts`), plus **pip/uv/pipx**\r\n(`pip install --dry-run` / `uv pip install --dry-run`) and **Linux host\r\npackages** (`apt`/`dnf`/`yum`'s own native dry-run). Ruby, Rust, Go,\r\nJava/Kotlin, C#, and Windows remain SCA-covered but not firewall-covered\r\nbelow — their package managers genuinely have no dry-run-without-side-effects\r\nequivalent to gate against, which is a mechanical constraint of each\r\necosystem's tooling, not an oversight. **Swift (SwiftPM/Carthage)** and\r\n**Flutter/Dart (pub)** are SCA-only today as well — see their sections\r\nbelow.\r\n\r\n---\r\n\r\n## Capability Matrix\r\n\r\n| Ecosystem | SCA | Firewall | SAST | Malware SAST | Reachability | License Compliance | Secrets |\r\n|---|:---:|:---:|:---:|:---:|:---:|:---:|:---:|\r\n| Node.js (npm/pnpm/bun) | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ |\r\n| Node.js (yarn) | ✅ | ❌ | ✅ | ✅ | ✅ | ✅ | ✅ |\r\n| Python (pip/uv/pipx/venv) | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ |\r\n| PHP (Composer) | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ |\r\n| Ruby (Bundler) | ✅ | ❌ | ✅ | ✅ | ✅ | ✅ | ✅ |\r\n| Rust (Cargo) | ✅ | ❌ | ✅ | ✅ | ✅ | ✅ | ✅ |\r\n| Go (modules) | ✅ | ❌ | ✅ | ✅ | ✅ | ✅ | ✅ |\r\n| Java / Kotlin (Maven) | ✅ | ❌ | ✅ | ✅ | ✅ | ✅ | ✅ |\r\n| C# / .NET (NuGet) | ✅ | ❌ | ✅ | ✅ | ✅ | ✅ | ✅ |\r\n| Swift (SwiftPM / Carthage) | ✅ | ❌ | ❌ | ❌ | ✅ | ⚠️ | ✅ |\r\n| Flutter / Dart (pub) | ✅ | ❌ | ❌ | ❌ | ✅ | ⚠️ | ✅ |\r\n| C | ❌ | ❌ | ✅ | ✅ | ❌ | ❌ | ✅ |\r\n| Docker images | ✅ (OS + app deps) | ✅ | — | — | — | ✅ | ✅ (in image) |\r\n| Kubernetes manifests | — | — | ✅ (misconfig) | — | — | — | ✅ |\r\n| Terraform / CloudFormation (IaC) | — | — | ✅ (misconfig) | — | — | — | ✅ |\r\n| Linux host (apt/dnf/yum) | ✅ | ✅ | — | — | — | ✅ | — |\r\n| Windows host | ✅ | ❌ | — | — | — | ✅ | — |\r\n| VS Code / Cursor / VSCodium extensions | ✅ | — | — | — | — | — | — |\r\n\r\n✅ = built and shipped · ⚠️ = partial, see that ecosystem's section · ❌ = not currently possible/present for a stated reason · — = not applicable to that layer\r\n\r\nCloud account misconfiguration scanning (AWS/GCP/Azure, via `ubel-cloud`) isn't tied to a dependency ecosystem, so it doesn't have a row here — see the [Cloud section](#cloud--aws--gcp--azure-misconfiguration-scanning) above.\r\n\r\n---\r\n\r\n## Node.js — npm / pnpm / bun / yarn\r\n\r\n**SCA:** Full lockfile parsing across npm v1/v2/v3, pnpm v5/v6/v9, yarn\r\nclassic and berry, and bun v0/v1. Dependency resolution walks the actual\r\ninstalled `node_modules` tree in addition to the lockfile, so it reflects\r\nwhat's really on disk, not just what the manifest declares. Scope\r\nassignment (production / dev / environment) is computed via BFS\r\npropagation from the manifest's declared dependency types down through the\r\nfull tree.\r\n\r\n**Firewall:** One of the ecosystems (alongside Docker and PHP/Composer) with a **lockfile-backed**\r\npre-install gate — atomic revert and TOCTOU hashing depend on there being a\r\nlockfile to revert *to*, which is specific to npm/pnpm/bun/Docker/Composer's\r\nmechanics. `npm`, `pnpm`, and `bun` each support a lockfile-only dry run\r\n(`--package-lock-only`, `--lockfile-only`, and a `node_modules`-untouched\r\nequivalent respectively) — UBEL resolves what *would* be installed, scans\r\nit against policy, and only proceeds if it's clean. TOCTOU is closed with\r\nSHA-256 integrity checks on the lockfile and `package.json` before and after\r\nresolution, and any policy-blocked change is rolled back atomically via\r\n`revert_lock_to_original`. **Yarn is deliberately excluded from firewalling**\r\n— not because UBEL doesn't support it, but because yarn itself has no\r\nside-effect-free dry-run equivalent to hook into: `yarn add` always writes\r\nto `node_modules` before you'd get a chance to block it. Yarn projects still\r\nget full SCA, SAST, secrets, and license coverage — they just can't be\r\ngated pre-install the way npm/pnpm/bun can, because yarn's own CLI doesn't\r\noffer a resolution step that stops short of writing to disk. (Python and\r\nLinux host packages also get a real pre-install gate now — see their\r\nsections below — just via a simpler revert-less mechanism, since neither\r\nhas a lockfile to roll back.)\r\n\r\n**SAST / Malware SAST:** Full three-pass (scan → verify → taint-trace)\r\nvulnerability pipeline and two-pass malware pipeline, JS/TS-aware chunking.\r\n\r\n**Reachability analysis:** Full import-graph reachability — a vulnerable\r\npackage is downgraded in priority if nothing in your code path actually\r\nimports the vulnerable module, and orphaned/unused dependencies get\r\nflagged separately. This is one of ten ecosystems with this capability\r\n(see the Reachability Analysis note under Cross-Cutting Capabilities).\r\n\r\n**Editor integration:** The VS Code/Cursor/VSCodium extension runs\r\nin-process (no shell-out), with dedicated commands for project scan, host\r\nscan, and — uniquely for this ecosystem — a scan of the **editor's own\r\ninstalled extensions**, since a malicious VS Code extension is itself a\r\nsupply-chain vector most tools never consider.\r\n\r\n---\r\n\r\n## Python — pip / uv / pipx / venv\r\n\r\n**SCA:** Resolves dependencies by walking virtual environment directories\r\ndirectly (not just parsing `requirements.txt`), so it reflects the actual\r\ninstalled environment, including transitive packages a manifest wouldn't\r\nshow on its own.\r\n\r\n**Firewall:** Available via `ubel-pip`/`ubel-uv`/`ubel-pipx` — two\r\ninstallers, same firewall shape, different dry-run mechanics under the\r\nhood. `ubel-pip` uses `pip`'s own `install --dry-run --report` (pip ≥22.2)\r\nto resolve the candidate set into a machine-readable report without\r\ninstalling anything; `ubel-uv` uses `uv pip install --dry-run` instead (uv\r\nhas no equivalent JSON report — its output is a flat `+ name==version`\r\nlist on stderr, see the honesty note below for what that costs). UBEL\r\nscans whichever resolution came back, and only then runs the real install\r\n— `pip install -r` or `uv pip install -r`, always against the same\r\ngenerated, exact-pinned requirements file either way. There's no lockfile\r\nhere, so there's no revert step the way npm/pnpm/bun have one: a\r\npolicy-blocked scan just means the real install never runs, nothing needs\r\nrolling back. `ubel-pip`/`ubel-uv` `check`/`install` accept packages on the\r\ncommand line, or fall back to `./requirements.txt`, then\r\n`./pyproject.toml`'s `[project]` dependencies, when none are given. A\r\nsuccessful *real* (non-dry-run) `install` — either installer — also syncs\r\nwhichever of those two files already exists in the project directory to\r\nmatch what's now actually installed: it's a re-run of the same scan\r\n`health` mode already does, not a separate `pip freeze`/`uv pip freeze`.\r\nExisting entries get their pinned version refreshed to the installed\r\nversion; anything newly installed but not yet listed gets appended; lines\r\nfor packages that *aren't* actually installed (comments, `-r`/`-e`/`-c`\r\ndirectives, a spec that failed to resolve) are left alone. Neither file is\r\ncreated if it doesn't already exist, and a sync failure is logged rather\r\nthan failing the install — the install itself already succeeded by that\r\npoint. `ubel-pipx` installs CLI tools into isolated, managed per-tool\r\nvirtual environments with a global shim on `PATH`, the same blast-radius\r\nreduction `pipx` itself provides — now gated by the same pre-install scan;\r\nthere's no `uv tool install`-equivalent CLI isolation mode here, only\r\npip's. One more `uv`-specific difference: `ubel-uv init` (and the first\r\n`check`/`install` that needs a venv) provisions it via uv's own `uv init\r\n--bare` + `uv venv` rather than the stdlib `venv` module the other five\r\nengines use — a real uv-recognized project (`pyproject.toml` present),\r\nnot just an interpreter uv happens to be pointed at via `--python`.\r\n\r\nTwo honesty notes, both of them limits of the underlying tools rather than\r\ngaps in UBEL's own implementation:\r\n- Unlike npm's lockfile dry-run, neither pip's nor uv's dry-run is\r\n  unconditionally side-effect-free — if a candidate package has no\r\n  pre-built wheel available, resolving its metadata can require building an\r\n  sdist, and building an sdist can execute arbitrary `setup.py`/build-backend\r\n  code. This is inherent to Python packaging resolution generally — how\r\n  `pip`/`uv` themselves resolve source-only packages — not something a\r\n  scan step layered on top of either tool could close off. Wheel-only\r\n  installs (the common case) don't have this gap.\r\n- `uv`-sourced scans carry less detail than `pip`-sourced ones in one\r\n  respect, and it traces back to what `uv pip install --dry-run` itself\r\n  exposes rather than a choice UBEL made: its output is a flat\r\n  `+ name==version` list rather than a dependency-annotated report, so it\r\n  carries no parent/child relationships — every uv-resolved component\r\n  comes back as its own root with empty\r\n  `introduced_by`/`parents`/`dependency_sequences`, unlike a pip-sourced\r\n  scan (pip's `--dry-run --report` includes that provenance; uv's dry-run\r\n  output simply doesn't). Vulnerability scanning itself is unaffected —\r\n  that's purl-based, not graph-based — but dependency-provenance detail\r\n  specifically is weaker for `uv` than for `pip` today. License data isn't\r\n  part of this gap: license classification only ever runs on `health`-mode\r\n  scans for every ecosystem UBEL supports, not just Python, so it's not\r\n  something a `check`/`install` dry-run needs from any installer.\r\n\r\n**SAST / Malware SAST:** Full coverage, same three-pass/two-pass pipelines.\r\n\r\n**Reachability analysis:** Fully covered, tracking `.py` files against the\r\nresolved dependency graph — one of ten ecosystems with this capability.\r\n\r\n---\r\n\r\n## PHP — Composer\r\n\r\n**SCA:** Resolves the dependency tree from `vendor/` and `composer.lock`.\r\n\r\n**Firewall:** Available via `ubel-composer` — the same lockfile-backed shape\r\nas npm/pnpm/bun, not the simpler revert-less mechanism pip/apt/dnf/yum use.\r\n`composer require`/`update --no-install --no-scripts` (Composer's own\r\nequivalent of `--package-lock-only`) resolves the candidate dependency tree\r\nand writes a candidate `composer.lock`/`composer.json` without touching\r\n`vendor/`; UBEL scans that candidate, and only then runs the real install —\r\n`composer install --no-scripts`. A policy-blocked scan reverts\r\n`composer.json`/`composer.lock` to their pre-scan state from an on-disk\r\nbackup, atomically, the same `revert_lock_to_original` path npm/pnpm/bun\r\nuse. TOCTOU is closed the same way too: SHA-256 checks on both files\r\nimmediately before the real install. Unlike pip's dry-run, there's no\r\nsdist-style caveat here — resolving a Composer dependency graph never runs\r\na package's own code, since Composer's lifecycle scripts only fire on an\r\nactual `install`/`update`, which is exactly why `--no-scripts` covers both\r\nthe dry-run and the real install.\r\n\r\n**SAST / Malware SAST:** Full coverage.\r\n\r\n**Reachability analysis:** Fully covered — `.php` files are scanned for\r\n`use`/`require`/`include` references against the resolved dependency\r\ngraph, same signal set (depth, scope, attack vector, import confirmation)\r\nas every other reachability-covered ecosystem.\r\n\r\n---\r\n\r\n## Ruby — Bundler\r\n\r\n**SCA:** Resolves from `Gemfile.lock`.\r\n\r\n**Firewall:** Not available — same reasoning as Rust/Go/Java/.NET below: no\r\nside-effect-free dry-run install path in Bundler for UBEL to hook into.\r\n\r\n**SAST / Malware SAST:** Full coverage, `.rb` chunking.\r\n\r\n**Reachability analysis:** Fully covered via `.rb` import scanning.\r\n\r\n---\r\n\r\n## Rust — Cargo\r\n\r\n**SCA:** Resolves from `Cargo.lock`, giving exact resolved versions rather\r\nthan semver ranges from `Cargo.toml`.\r\n\r\n**Firewall:** Not available — `cargo add`/`cargo build` don't offer an\r\nequivalent gate point.\r\n\r\n**SAST / Malware SAST:** Full coverage.\r\n\r\n**Reachability analysis:** Fully covered via `.rs` import scanning.\r\n\r\n---\r\n\r\n## Go — modules\r\n\r\n**SCA:** Resolves from `go.sum`, which pins exact versions and hashes\r\nalready, giving high-confidence version matching against OSV.\r\n\r\n**Firewall:** Not available.\r\n\r\n**SAST / Malware SAST:** Full coverage.\r\n\r\n**Reachability analysis:** Fully covered via `.go` import scanning.\r\n\r\n---\r\n\r\n## Java / Kotlin — Maven\r\n\r\n**SCA:** Resolves the dependency tree from `pom.xml`, following transitive\r\nMaven resolution.\r\n\r\n**Firewall:** Not available.\r\n\r\n**SAST / Malware SAST:** Full coverage; Java and Kotlin are tracked as\r\nseparate language families in the catalog, so idioms specific to each\r\n(e.g., Kotlin null-safety bypasses vs. Java reflection abuse) get\r\ndistinct signal sets rather than one being shoehorned into the other's\r\nruleset.\r\n\r\n**Reachability analysis:** Fully covered — `.java`, `.kt`, `.groovy`, and\r\n`.scala` files are all scanned under the same `maven` reachability key.\r\n\r\n**Note:** Gradle-based projects aren't mentioned as a separately-resolved\r\nbuild system — Maven-style resolution is the documented path for this\r\necosystem today.\r\n\r\n---\r\n\r\n## C# / .NET — NuGet\r\n\r\n**SCA:** Resolves from `packages.lock.json` where present, falling back to\r\n`obj/project.assets.json` (the MSBuild-generated resolved graph) when a\r\nproject doesn't use lock-file mode.\r\n\r\n**Firewall:** Not available.\r\n\r\n**SAST / Malware SAST:** Full coverage.\r\n\r\n**Reachability analysis:** Fully covered — `.cs`, `.vb`, `.fs`, and `.fsx`\r\nfiles are all scanned under the same `nuget` reachability key.\r\n\r\n---\r\n\r\n## Swift — SwiftPM / Carthage\r\n\r\n**SCA:** Resolves from the lockfiles Swift tooling already writes, so\r\nnothing needs to be built or installed first:\r\n\r\n- `Package.resolved` (SwiftPM formats v1, v2, and v3) — next to a\r\n  `Package.swift`, inside an Xcode workspace at\r\n  `<X>.xcworkspace/xcshareddata/swiftpm/`, or inside an Xcode project at\r\n  `<X>.xcodeproj/project.xcworkspace/xcshareddata/swiftpm/`.\r\n- `.build/workspace-state.json` — fallback for a package whose\r\n  `Package.resolved` wasn't committed (common for libraries that gitignore\r\n  it).\r\n- `Cartfile.resolved` (Carthage) — `binary` entries are skipped, since they\r\n  carry no repository identity.\r\n\r\nPackages are reported as `pkg:swift/<host>/<owner>/<repo>@<version>` (OSV\r\necosystem `SwiftURL`), with a leading `v` stripped from release tags. Local\r\npackages (`fileSystem` / `localSourceControl` pins) are first-party code and\r\naren't reported. A pin that resolves to a branch or a bare commit instead of\r\na release tag is inventoried with an empty version and dropped from OSV\r\nqueries, because a commit hash isn't a version OSV can range-match.\r\n\r\nCocoaPods (`Podfile.lock`) is intentionally not scanned: OSV has no\r\nCocoaPods ecosystem, so those packages could never match an advisory.\r\n\r\n**Scopes:** None of these lockfiles distinguish dev from prod, so every\r\nSwift package is reported as `prod`.\r\n\r\n**Firewall:** Not available — Swift is SCA-only today.\r\n\r\n**SAST / Malware SAST:** Not covered — Swift isn't one of the language\r\nfamilies in the SAST or malware catalogs. `.swift` files are still included\r\nin Secrets detection.\r\n\r\n**Reachability analysis:** Covered — `.swift` files (plus `.m`/`.mm`/`.h`) are\r\nscanned for `import <Module>` / `@import` / `#import <Module/…>` references,\r\nwith repository-to-module mapping (e.g. `swift-log` → `Logging`).\r\n\r\n**License compliance:** `Package.resolved` and `Cartfile.resolved` don't\r\nrecord licenses, so every Swift package is inventoried with license\r\n`unknown`.\r\n\r\n---\r\n\r\n## Flutter / Dart — pub\r\n\r\n**SCA:** A directory is scanned when it contains `pubspec.lock` or — for\r\npackages and libraries that don't commit their lockfile —\r\n`.dart_tool/package_config.json`, which `dart pub get` / `flutter pub get`\r\nwrites. `pubspec.lock` is preferred when both exist: it carries each\r\npackage's version, source (hosted, git, path, or sdk), and dependency kind.\r\nFrom the `package_config.json` fallback only hosted packages can be\r\nrecovered (their version comes from the pub-cache directory name); git, SDK,\r\nand relative-path packages are skipped there.\r\n\r\nPackages are reported as `pkg:pub/<name>@<version>`, with\r\n`?repository_url=<url>` for a package hosted on a non-pub.dev registry and\r\n`?vcs_url=<url>` for a git dependency. `sdk` sources (`flutter`,\r\n`flutter_test`, …) and `path` sources are skipped — first-party or toolchain\r\ncode, not installed third-party packages.\r\n\r\n**Scopes:** From `pubspec.lock`: `direct main` and `direct overridden` →\r\n`prod`, `direct dev` → `dev`, and `transitive` → `prod` (the lockfile\r\ndoesn't record whether a transitive dependency is reached from dev or main,\r\nso the conservative default is used). Packages recovered from the\r\n`package_config.json` fallback carry no dev/main signal and are reported as\r\n`prod`.\r\n\r\n**Dependency graph:** `pubspec.lock` has no dependency graph, so Flutter/Dart\r\npackages are reported without introduced-by/parent edges.\r\n\r\n**Known limitation:** OSV matches on package name. A package from a private\r\nregistry or a git repository that shares its name with a pub.dev package can\r\nbe matched against that package's advisories; the `repository_url` /\r\n`vcs_url` qualifier keeps the identity distinct in the inventory but doesn't\r\nstop the OSV lookup.\r\n\r\n**Firewall:** Not available — Flutter/Dart is SCA-only today.\r\n\r\n**SAST / Malware SAST:** Not covered — Dart isn't one of the language\r\nfamilies in the SAST or malware catalogs.\r\n\r\n**Reachability analysis:** Covered — `.dart` files are scanned for\r\n`import`/`export 'package:<name>/…'` references, including conditional-import\r\ncontinuation lines. A federated platform implementation (e.g.\r\n`url_launcher_android`) is also matched via its app-facing package.\r\n\r\n**License compliance:** `pubspec.lock` doesn't record licenses, so every\r\nFlutter/Dart package is inventoried with license `unknown`.\r\n\r\n---\r\n\r\n## C (bare, no package manager)\r\n\r\n**SCA:** Not applicable — C has no standard ecosystem-level package\r\nmanager/lockfile for UBEL to resolve a dependency tree from, so there's no\r\nSCA/vulnerability-matching layer for C the way there is for the\r\nlockfile-based ecosystems above.\r\n\r\n**SAST / Malware SAST:** Covered as its own language family in the\r\ncatalog — memory-safety and injection-class findings are scanned for\r\ndirectly in source, independent of any dependency graph.\r\n\r\n**License compliance:** Not applicable, for the same reason as SCA — no\r\nper-package manifest to read a declared license from.\r\n\r\n---\r\n\r\n## Docker — container images\r\n\r\n**SCA:** The most complete single-target scan in UBEL. Pulls (or reuses a\r\nlocal) image or accepts an already-exported uncompressed `.tar` — never\r\nruns the image's `ENTRYPOINT`/`CMD` — exports its filesystem to a temp dir,\r\nand scans that filesystem exactly like any other project root: OS packages\r\nvia the Linux host scanner *and* every application-level ecosystem's\r\ndependencies found inside the image (Node, Python, PHP, etc., all at once,\r\nvia `full_stack`).\r\n\r\n**Firewall:** Docker gets **true pre-install (here, pre-deploy) gating**,\r\nwith three modes controlling what happens to the image after scanning:\r\n- `health` — scan only, image left exactly as found.\r\n- `check` — scan, then always remove the image afterward (throwaway vetting).\r\n- `install` — scan, then remove the image *only if* the scan results in a\r\n  policy block; a clean scan leaves it in place.\r\n\r\n`--no-pull` scans an image that only exists locally (e.g., right after\r\n`docker build`, before it's ever pushed to a registry) — this is the\r\n\"vet before you ship\" path. `--keep` retains the extracted root filesystem\r\nfor debugging. Pointing this at a CI-built image before push, or at a\r\nthird-party base image before you adopt it, is the intended pre-deploy\r\nfirewall use.\r\n\r\n**Malware/Secrets/License:** All inherited from whatever's found inside the\r\nimage — an image with a compromised npm package, a hardcoded AWS key in a\r\nbaked-in `.env`, or a GPL-licensed binary bundled into a proprietary image\r\nall get caught the same way they would in a live checkout.\r\n\r\n---\r\n\r\n## Kubernetes manifests\r\n\r\n**Coverage:** Not a separate scanner — Kubernetes YAML is treated as its\r\nown chunkable language family inside the SAST catalog, so misconfigurations\r\nget scanned with the same LLM-driven pipeline as source code. Verified\r\nclasses include: overly permissive RBAC / `ClusterRoleBinding`s, containers\r\nconfigured to run as root, missing `NetworkPolicy` isolation on services\r\nexposed via `LoadBalancer`/`NodePort`, and similar cluster-hardening gaps.\r\n\r\n**Not covered:** Live cluster state — this scans the YAML *files* in your\r\nrepo, not a running cluster's actual applied configuration or drift from\r\nthose files. There's no `kubectl`-based live posture check.\r\n\r\n---\r\n\r\n## Terraform / CloudFormation (Infrastructure-as-Code)\r\n\r\n**Coverage:** Same mechanism as Kubernetes above — IaC is its own language\r\nfamily in the catalog. Confirmed classes include hardcoded secrets\r\nembedded directly in `.tf`/CloudFormation templates and resources\r\nprovisioned with encryption-at-rest disabled.\r\n\r\n**Not covered:** Live cloud account state. This is static analysis of the\r\nIaC *source* — it will not detect drift where the deployed resource no\r\nlonger matches what the template says, and it isn't a cloud security\r\nposture management (CSPM) tool that queries your cloud provider's API for\r\nthe actual state of running resources.\r\n\r\n---\r\n\r\n## Linux host (apt / dnf / yum)\r\n\r\n**SCA:** `LinuxHostScanner` inventories installed OS packages and matches\r\nthem against CPE/CVE data — this is what backs both the standalone\r\n`ubel-platform` host scan and the OS-package half of every Docker image\r\nscan.\r\n\r\n**Firewall:** Available via three separate binaries — `ubel-apt`,\r\n`ubel-dnf`, `ubel-yum` — each bound to exactly one native package manager,\r\nwith no auto-detection between them (the same one-binary-per-tool shape as\r\n`ubel-npm`/`ubel-pnpm`/`ubel-bun`; running `ubel-dnf` on a box that only has\r\n`apt` fails clearly rather than silently doing the wrong thing). Each uses\r\nits package manager's own native dry-run — `apt-get -s` (simulate) for\r\nDebian/Ubuntu, `dnf --assumeno` for RHEL 8+/AlmaLinux/Rocky,\r\n`yum --assumeno` for RHEL 7 — to resolve what *would* be installed (name,\r\nversion, and for apt, the source repo/arch) without installing it. UBEL\r\nscans that resolution and only then runs the real\r\n`sudo apt/dnf/yum install -y`. As with pip, there's no lockfile, so a\r\nblocked scan just means the real install never runs — nothing to revert.\r\nReports and policy live under `~/.ubel/local` specifically so that routine\r\n`health`/`check` use never needs elevated privileges; only the real install\r\nstep does, same as running the package manager yourself.\r\n\r\n**License compliance:** Fully applied. Per-package license strings are\r\nextracted from rpm metadata, `/usr/share/doc/<pkg>/copyright` for\r\ndpkg-based systems, and apk metadata, then fed through the same SPDX\r\nnormalization/OSI/risk classification layer as every other ecosystem — it\r\nisn't a separate, lesser pipeline for OS packages.\r\n\r\n---\r\n\r\n## Windows host\r\n\r\n**SCA:** `WindowsHostScanner` mirrors the Linux host scanner's role for\r\nWindows — installed software/package inventory matched against CPE/CVE.\r\n\r\n**Firewall:** Not available. Unlike Linux's `apt-get -s`/`dnf --assumeno`,\r\nthere's no equivalent dry-run resolution UBEL can hook into for Windows'\r\npackage managers/installers today — this remains health/detection scanning\r\nof what's already on the machine, not a gate on what's about to be\r\ninstalled.\r\n\r\n**License compliance:** Fully applied, via its own `licenseFor()` mapping\r\nfeeding the same classification pipeline as every other ecosystem.\r\n\r\n---\r\n\r\n## Cross-Cutting Capabilities\r\n\r\n### Reachability Analysis — 10 ecosystems via import-graph confirmation\r\n\r\nEvery vulnerability is annotated with a reachability verdict derived from\r\ndependency depth, scope (prod/dev/env), attack vector, orphan-tool\r\ndetection, and — where source is available — actual import/require\r\nscanning that confirms whether the vulnerable module is ever referenced.\r\nThe import-scan half of this is implemented for **Python (`.py`), Node.js\r\n(`.js`/`.ts`/`.mjs`/`.cjs`/`.jsx`/`.tsx`), Maven/Java+Kotlin (`.java`,\r\n`.kt`, `.groovy`, `.scala`), NuGet/C# (`.cs`, `.vb`, `.fs`, `.fsx`), PHP\r\n(`.php`), Go (`.go`), Cargo/Rust (`.rs`), RubyGems/Ruby (`.rb`), Flutter/Dart\r\n(`.dart`), and Swift (`.swift`, plus `.m`/`.mm`/`.h` for Objective-C interop)** —\r\nevery SCA ecosystem except C. Dart matches `import`/`export 'package:<name>/…'`;\r\nSwift maps each package's repository to its module names (e.g. `swift-log` →\r\n`Logging`) and matches `import <Module>`, `@import`, and `#import <Module/…>`. A known distribution-name-to-\r\nimport-name override table (e.g. `beautifulsoup4` → `bs4`,\r\n`pyyaml` → `yaml`, `opencv-python` → `cv2`) keeps the import match accurate\r\neven where the published package name and the name you actually import\r\ndiverge. C, OS packages, Docker, Kubernetes, and IaC don't get this layer,\r\nsince there's no per-package \"is this imported by my source\" question that\r\napplies to them the same way.\r\n\r\n### Secrets Detection — every ecosystem, uniformly\r\n\r\nSecrets scanning is deliberately **ecosystem-independent**: it's a plain\r\nfile walk over source and config file extensions (`.js`, `.py`, `.rb`,\r\n`.go`, `.java`, `.php`, `.cs`, `.rs`, `.kt`, `.swift`, `.json`, `.yml`,\r\n`.yaml`, config files, etc.), pattern-matched against a ruleset ported from\r\nTrivy's secret rules (separately attributed and licensed — only that\r\nvendored ruleset is Apache-2.0; the scanner code around it isn't). It\r\nnever touches `node_modules`, `vendor/`, `target/`, virtual environments, or\r\nany other dependency directory — it's scanning *your* code for accidental\r\ncommits, not your dependencies. This means it runs identically whether\r\nyou're in a Node repo, a Python repo, a Kubernetes manifests repo, or an\r\nimage filesystem — there's no per-language variance in what it can find.\r\nIt's a pure in-memory scanner with no disk writes of its own; the caller\r\n(main engine) decides whether findings fold into the JSON/HTML/SARIF\r\nreport.\r\n\r\n### License Compliance — every ecosystem, including OS packages\r\n\r\nA zero-dependency, no-network normalization layer that takes whatever\r\ninconsistent shape a package manager reports a license in — missing/null,\r\nfree text (\"Apache 2.0\", \"BSD\"), npm's `UNLICENSED` sentinel (proprietary —\r\n**not** the SPDX \"Unlicense\" public-domain license, a common footgun),\r\n`SEE LICENSE IN <file>` references, Python trove classifiers, full SPDX\r\nexpressions like `(MIT OR Apache-2.0)` — and normalizes it to a canonical\r\nSPDX identifier, checks it against a c","readmeFilename":"README.md"}