{"_id":"@chengyixu/depcheck-ai","_rev":"2-053908004887d0c20c3f91a9ed5c50e4","name":"@chengyixu/depcheck-ai","dist-tags":{"latest":"1.0.1"},"versions":{"1.0.0":{"name":"@chengyixu/depcheck-ai","version":"1.0.0","keywords":["dependency","audit","security","vulnerability","npm-audit","outdated","upgrade","deprecated","package-checker","depcheck","cve","supply-chain-security","risk-scoring","ci-cd","semver","node-security","dependency-management"],"author":{"name":"Chengyi Xu","email":"chengyixu@outlook.com"},"license":"MIT","_id":"@chengyixu/depcheck-ai@1.0.0","maintainers":[{"name":"chengyixu","email":"Chengyi_xu@outlook.com"}],"homepage":"https://github.com/chengyixu/depcheck-ai#readme","bugs":{"url":"https://github.com/chengyixu/depcheck-ai/issues"},"bin":{"depcheck-ai":"dist/index.js"},"dist":{"shasum":"5b6fec33634aa4b77783d881251db26d1d66b007","tarball":"https://registry.npmjs.org/@chengyixu/depcheck-ai/-/depcheck-ai-1.0.0.tgz","fileCount":7,"integrity":"sha512-vS8T2/HOSwDHp3Y1Vyw25gOLQSur0Ve2+U3H3nsX3rENlgaX5gs6rPWKHG9o/Nh97GIzPBJUzzsJmQZpULc+aQ==","signatures":[{"sig":"MEUCIQD91yJyT3D3i+brD2m3f7L+S5VkdXhYzJFKLBPnyQwB8QIgVdsW0NoMo2OrXEBvboEZNpLCMIXAK933FKPfzYl+aak=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":61853},"main":"dist/index.js","types":"./dist/index.d.ts","engines":{"node":">=16.0.0"},"scripts":{"build":"tsc","start":"node dist/index.js","prepublishOnly":"npm run build"},"_npmUser":{"name":"chengyixu","email":"Chengyi_xu@outlook.com"},"repository":{"url":"git+https://github.com/chengyixu/depcheck-ai.git","type":"git"},"_npmVersion":"11.6.2","description":"Smart dependency auditing for Node.js -- find outdated, vulnerable, and deprecated npm packages with risk scoring, upgrade suggestions, and CI/CD integration","directories":{},"_nodeVersion":"24.11.1","dependencies":{"ora":"^5.4.1","chalk":"^4.1.2","semver":"^7.6.0","commander":"^12.0.0","cli-table3":"^0.6.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.3.0","@types/node":"^20.0.0","@types/semver":"^7.5.0"},"_npmOperationalInternal":{"tmp":"tmp/depcheck-ai_1.0.0_1773902646267_0.11049335428724616","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@chengyixu/depcheck-ai","version":"1.0.1","description":"Smart dependency auditing for Node.js -- find outdated, vulnerable, and deprecated npm packages with risk scoring, upgrade suggestions, and CI/CD integration","main":"dist/index.js","bin":{"depcheck-ai":"dist/index.js"},"scripts":{"build":"tsc","start":"node dist/index.js","prepublishOnly":"npm run build"},"keywords":["dependency","audit","security","vulnerability","npm-audit","outdated","upgrade","deprecated","package-checker","depcheck","cve","supply-chain-security","risk-scoring","ci-cd","semver","node-security","dependency-management"],"author":{"name":"Chengyi Xu","email":"chengyixu@outlook.com"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/chengyixu/depcheck-ai.git"},"homepage":"https://github.com/chengyixu/depcheck-ai#readme","bugs":{"url":"https://github.com/chengyixu/depcheck-ai/issues"},"engines":{"node":">=16.0.0"},"publishConfig":{"access":"public"},"devDependencies":{"typescript":"^5.3.0","@types/node":"^20.0.0","@types/semver":"^7.5.0"},"dependencies":{"semver":"^7.6.0","chalk":"^4.1.2","ora":"^5.4.1","commander":"^12.0.0","cli-table3":"^0.6.3"},"types":"./dist/index.d.ts","_id":"@chengyixu/depcheck-ai@1.0.1","_nodeVersion":"24.11.1","_npmVersion":"11.6.2","dist":{"integrity":"sha512-dw+vERJEuyNhjjSmDQO+UsJALjBvG7RxgWJFy1Xmo9JOKzlrTqFKvDlLSyYe+xHzOtCeUOexoJ5RZ4ddP5s7ww==","shasum":"c098807fbf1a2de25624ae95b6247ed26f3369eb","tarball":"https://registry.npmjs.org/@chengyixu/depcheck-ai/-/depcheck-ai-1.0.1.tgz","fileCount":7,"unpackedSize":61853,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIF0abAd32RicAcupu3dqQqQfaYxllJUYt2SeIbdb5IFkAiBX2kLh8HK2ycSpVG0bsd993SdmD0fCczQanWVska2ouw=="}]},"_npmUser":{"name":"chengyixu","email":"Chengyi_xu@outlook.com"},"directories":{},"maintainers":[{"name":"chengyixu","email":"Chengyi_xu@outlook.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/depcheck-ai_1.0.1_1773902734441_0.05889000713047543"},"_hasShrinkwrap":false}},"time":{"created":"2026-03-19T06:44:06.201Z","modified":"2026-03-19T06:45:34.714Z","1.0.0":"2026-03-19T06:44:06.449Z","1.0.1":"2026-03-19T06:45:34.591Z"},"bugs":{"url":"https://github.com/chengyixu/depcheck-ai/issues"},"author":{"name":"Chengyi Xu","email":"chengyixu@outlook.com"},"license":"MIT","homepage":"https://github.com/chengyixu/depcheck-ai#readme","keywords":["dependency","audit","security","vulnerability","npm-audit","outdated","upgrade","deprecated","package-checker","depcheck","cve","supply-chain-security","risk-scoring","ci-cd","semver","node-security","dependency-management"],"repository":{"type":"git","url":"git+https://github.com/chengyixu/depcheck-ai.git"},"description":"Smart dependency auditing for Node.js -- find outdated, vulnerable, and deprecated npm packages with risk scoring, upgrade suggestions, and CI/CD integration","maintainers":[{"name":"chengyixu","email":"Chengyi_xu@outlook.com"}],"readme":"# depcheck-ai\n\n[![npm version](https://img.shields.io/npm/v/@chengyixu/depcheck-ai.svg)](https://www.npmjs.com/package/@chengyixu/depcheck-ai)\n[![npm downloads](https://img.shields.io/npm/dm/@chengyixu/depcheck-ai.svg)](https://www.npmjs.com/package/@chengyixu/depcheck-ai)\n[![license](https://img.shields.io/npm/l/@chengyixu/depcheck-ai.svg)](https://github.com/chengyixu/depcheck-ai/blob/main/LICENSE)\n\n> Smart dependency auditing for Node.js projects -- find outdated, vulnerable, and deprecated packages with risk scoring and upgrade suggestions.\n\n`npm audit` only catches known CVEs. `npm outdated` only shows version diffs. **depcheck-ai** combines both and adds intelligent risk scoring, smart upgrade paths, and beautiful reports.\n\n## Demo\n\n```\n$ depcheck-ai\n\n  depcheck-ai  Dependency Audit Report\n  =====================================\n\n  Project: my-app v2.1.0\n  Scanned: 2026-03-19T14:30:00.000Z\n\n  Summary\n  -------\n  Total dependencies:   24\n  Outdated:              8\n  Vulnerable:            2\n  Deprecated:            1\n  Overall health:       WARNING\n\n  +-------------------+----------+----------+--------+----------+\n  | Package           | Current  | Latest   | Risk   | Action   |\n  +-------------------+----------+----------+--------+----------+\n  | lodash            | 4.17.15  | 4.17.21  | HIGH   | Upgrade  |\n  | express           | 4.18.1   | 4.21.0   | LOW    | Optional |\n  | request           | 2.88.2   | -        | CRIT   | Replace  |\n  | chalk             | 4.1.2    | 5.3.0    | SAFE   | Major    |\n  +-------------------+----------+----------+--------+----------+\n\n  Vulnerable packages:\n    lodash@4.17.15 - Prototype Pollution (GHSA-xxxx)\n      Patched in: >=4.17.21\n      Suggested:  npm install lodash@4.17.21\n\n  Deprecated packages:\n    request@2.88.2 - Use 'undici' or 'node-fetch' instead\n\n  Exit code: 1 (WARNING)\n```\n\n## Install\n\n```bash\nnpm install -g @chengyixu/depcheck-ai\n```\n\nOr run without installing:\n\n```bash\nnpx @chengyixu/depcheck-ai\n```\n\n## Usage\n\n### Scan the current project\n\n```bash\ndepcheck-ai\n```\n\n### Scan a specific directory\n\n```bash\ndepcheck-ai /path/to/project\n```\n\n### JSON output for CI/CD pipelines\n\n```bash\ndepcheck-ai --json\n```\n\n### Generate an HTML report\n\n```bash\ndepcheck-ai --html report.html\n```\n\n### Filter by dependency type\n\n```bash\n# Only production dependencies\ndepcheck-ai --prod\n\n# Only dev dependencies\ndepcheck-ai --dev\n\n# Include peer dependencies\ndepcheck-ai --peer\n```\n\n### Verbose mode (full upgrade details)\n\n```bash\ndepcheck-ai --verbose\n```\n\n## CI/CD Integration\n\n```yaml\n# GitHub Actions\n- name: Dependency audit\n  run: npx @chengyixu/depcheck-ai --json > audit.json\n\n# GitLab CI\ndependency_audit:\n  script:\n    - npx @chengyixu/depcheck-ai --json > audit.json\n  artifacts:\n    paths:\n      - audit.json\n```\n\nUse exit codes to gate deployments:\n\n| Code | Meaning |\n|------|---------|\n| 0 | Healthy -- no issues or only minor outdated packages |\n| 1 | Warning -- vulnerabilities or high-risk outdated packages |\n| 2 | Danger -- critical vulnerabilities found |\n\n## Why depcheck-ai over alternatives?\n\n| Feature | depcheck-ai | npm audit | npm outdated | snyk |\n|---------|:-----------:|:---------:|:------------:|:----:|\n| Vulnerability scanning | Yes | Yes | No | Yes |\n| Outdated detection | Yes | No | Yes | Partial |\n| Deprecated package alerts | Yes | No | No | No |\n| Risk-level scoring | Yes | No | No | Partial |\n| Smart upgrade suggestions | Yes | No | No | Yes |\n| HTML reports | Yes | No | No | Yes |\n| JSON output | Yes | Yes | Yes | Yes |\n| CI exit codes | Yes | Yes | No | Yes |\n| Zero config | Yes | Yes | Yes | No |\n| Free & open source | Yes | Yes | Yes | Freemium |\n\n## Features\n\n- **Vulnerability scanning** -- checks the npm advisory database for known CVEs\n- **Outdated detection** -- queries the npm registry for latest versions\n- **Deprecated package alerts** -- flags packages that authors have deprecated\n- **Risk scoring** -- assigns risk levels (safe/low/medium/high/critical) based on multiple factors\n- **Smart upgrade paths** -- suggests safe patch/minor updates vs. major upgrades needing review\n- **Multiple output formats** -- CLI tables, JSON, and HTML reports\n- **Fast parallel scanning** -- checks 8 packages concurrently\n- **CI/CD ready** -- exit codes and JSON output for automated pipelines\n- **Zero config** -- just point it at any directory with a package.json\n\n## License\n\nMIT\n","readmeFilename":"README.md"}