{"_id":"@dawnswwwww/open-security","_rev":"13-1839ecf89bb733a3f55b8ac90ac78496","name":"@dawnswwwww/open-security","dist-tags":{"latest":"0.2.2"},"versions":{"0.1.0":{"name":"@dawnswwwww/open-security","version":"0.1.0","license":"Apache-2.0","_id":"@dawnswwwww/open-security@0.1.0","maintainers":[{"name":"dawnswwwww","email":"wxn_em@163.com"}],"homepage":"https://github.com/dawnswwwww/open-security#readme","bugs":{"url":"https://github.com/dawnswwwww/open-security/issues"},"bin":{"open-security":"dist/cli.js"},"dist":{"shasum":"1b9db34df161742b6a7267c39a3535fc4731e259","tarball":"https://registry.npmjs.org/@dawnswwwww/open-security/-/open-security-0.1.0.tgz","fileCount":73,"integrity":"sha512-OM75Pl5Kch1ITJS/PEN/JZ8j9tPUsA2yjfe0fv0ofTP+ZVEsvSG64LD0FgNCS5UkU+6DYODYX+ILjviHTrAFTQ==","signatures":[{"sig":"MEYCIQDLgRwqyKNpA1IzPRQBIIU8mUFR59C9dyx4TxXg+xCEHwIhANWKwltDvzzViEeYP2mg2J180KgVXR68FGDh1SKKVTjs","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@dawnswwwww%2fopen-security@0.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":221551},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"3130e460b44f99ea4623a133d8922304d41235df","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc -p tsconfig.json","prepublishOnly":"npm run build"},"_npmUser":{"name":"dawnswwwww","email":"wxn_em@163.com"},"repository":{"url":"git+https://github.com/dawnswwwww/open-security.git","type":"git"},"_npmVersion":"10.9.8","description":"LLM-driven security diff scanner with a pluggable agent runtime (Claude Agent SDK by default, ACP-compatible agents supported)","directories":{},"_nodeVersion":"22.23.1","dependencies":{"zod":"^3.24.0","commander":"^13.0.0","@agentclientprotocol/sdk":"^1.3.0","@anthropic-ai/claude-agent-sdk":"^0.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.10.0"},"_npmOperationalInternal":{"tmp":"tmp/open-security_0.1.0_1786697722995_0.7260586807392122","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@dawnswwwww/open-security","version":"0.1.1","license":"Apache-2.0","_id":"@dawnswwwww/open-security@0.1.1","maintainers":[{"name":"dawnswwwww","email":"wxn_em@163.com"}],"homepage":"https://github.com/dawnswwwww/open-security#readme","bugs":{"url":"https://github.com/dawnswwwww/open-security/issues"},"bin":{"open-security":"dist/cli.js"},"dist":{"shasum":"6b5f02badc254f72850fe563114903388f406c50","tarball":"https://registry.npmjs.org/@dawnswwwww/open-security/-/open-security-0.1.1.tgz","fileCount":73,"integrity":"sha512-bVlv0rKyIWl86qAZs3dgS6uUhDVWG3KpL95OzXZAYMKpNbnyl+OCocPACDJtE4Pu4KxDi5s3MC962Oe54cu4Yg==","signatures":[{"sig":"MEUCIQDAtMTos76dQv1LD/8QmrDlmd/SdUJdXgvfa8ZCiGQtYQIgHmgAuuLPoGhmQw6CdumIig0z5XHwlUQ33m1OyLqHrMU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@dawnswwwww%2fopen-security@0.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":224475},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"b8db97d5d0ef712b008e820b79b26cff548087b9","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc -p tsconfig.json","prepublishOnly":"npm run build"},"_npmUser":{"name":"dawnswwwww","email":"wxn_em@163.com"},"repository":{"url":"git+https://github.com/dawnswwwww/open-security.git","type":"git"},"_npmVersion":"10.9.8","description":"LLM-driven security diff scanner with a pluggable agent runtime (Claude Agent SDK by default, ACP-compatible agents supported)","directories":{},"_nodeVersion":"22.23.1","dependencies":{"zod":"^3.24.0","commander":"^13.0.0","@agentclientprotocol/sdk":"^1.3.0","@anthropic-ai/claude-agent-sdk":"^0.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.10.0"},"_npmOperationalInternal":{"tmp":"tmp/open-security_0.1.1_1786698641110_0.6026391010761829","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@dawnswwwww/open-security","version":"0.1.2","license":"Apache-2.0","_id":"@dawnswwwww/open-security@0.1.2","maintainers":[{"name":"dawnswwwww","email":"wxn_em@163.com"}],"homepage":"https://github.com/dawnswwwww/open-security#readme","bugs":{"url":"https://github.com/dawnswwwww/open-security/issues"},"bin":{"open-security":"dist/cli.js"},"dist":{"shasum":"7b2a6b1657fc5d6afce3cc356dd35f914eeeee8f","tarball":"https://registry.npmjs.org/@dawnswwwww/open-security/-/open-security-0.1.2.tgz","fileCount":76,"integrity":"sha512-PtDkOHawTLoc00jHhwIkmKZD2ep01+WXTBg+wmUYsXC3iuytMNWpVBPep4yfyQ2FT7SAT/A7z73rwBvvmcicbg==","signatures":[{"sig":"MEUCIQCQ2rl1YXIbGgjOtDWFZEFrM+6CJ62Khn4imxDzdrXHdgIgI/rCQry5+tdPjJ9cgS8pLIpjaPFi2mV+nEnlm47k9uU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@dawnswwwww%2fopen-security@0.1.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":231228},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"8fd92770ef60784b7b2bbc05c2c3c801d7f9c76b","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc -p tsconfig.json","prepublishOnly":"npm run build"},"_npmUser":{"name":"dawnswwwww","email":"wxn_em@163.com"},"repository":{"url":"git+https://github.com/dawnswwwww/open-security.git","type":"git"},"_npmVersion":"10.9.8","description":"LLM-driven security diff scanner with a pluggable agent runtime (Claude Agent SDK by default, ACP-compatible agents supported)","directories":{},"_nodeVersion":"22.23.1","dependencies":{"zod":"^3.24.0","commander":"^13.0.0","@agentclientprotocol/sdk":"^1.3.0","@anthropic-ai/claude-agent-sdk":"^0.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.10.0"},"_npmOperationalInternal":{"tmp":"tmp/open-security_0.1.2_1786699459876_0.3116555004864625","host":"s3://npm-registry-packages-npm-production"}},"0.1.3":{"name":"@dawnswwwww/open-security","version":"0.1.3","license":"Apache-2.0","_id":"@dawnswwwww/open-security@0.1.3","maintainers":[{"name":"dawnswwwww","email":"wxn_em@163.com"}],"homepage":"https://github.com/dawnswwwww/open-security#readme","bugs":{"url":"https://github.com/dawnswwwww/open-security/issues"},"bin":{"open-security":"dist/cli.js"},"dist":{"shasum":"d1daadbd35a8398cebb80f0e340cc144131d5c74","tarball":"https://registry.npmjs.org/@dawnswwwww/open-security/-/open-security-0.1.3.tgz","fileCount":76,"integrity":"sha512-Ich/XEHaTl1rRU1P71MchxrJmL82XaamSb94y0fw1dzCDRNZp9Q6xEHd1+UGm57UGhQl3hF13sZan0A0S1LOAQ==","signatures":[{"sig":"MEUCIQC/CPhp9nAKfhhpxuy+g4Blfs4gdboaNhV3QsVVjz9yAwIgWdYfrCZm9OwidRsTiCbvW8nFzmcLy1Qpih9BS80+Pj8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@dawnswwwww%2fopen-security@0.1.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":231865},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"7cf1985ab3515ca2549f465e7b83412224daa410","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc -p tsconfig.json","prepublishOnly":"npm run build"},"_npmUser":{"name":"dawnswwwww","email":"wxn_em@163.com"},"repository":{"url":"git+https://github.com/dawnswwwww/open-security.git","type":"git"},"_npmVersion":"10.9.8","description":"LLM-driven security diff scanner with a pluggable agent runtime (Claude Agent SDK by default, ACP-compatible agents supported)","directories":{},"_nodeVersion":"22.23.2","dependencies":{"zod":"^3.24.0","commander":"^13.0.0","@agentclientprotocol/sdk":"^1.3.0","@anthropic-ai/claude-agent-sdk":"^0.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.10.0"},"_npmOperationalInternal":{"tmp":"tmp/open-security_0.1.3_1786699575730_0.10883379115806191","host":"s3://npm-registry-packages-npm-production"}},"0.1.4":{"name":"@dawnswwwww/open-security","version":"0.1.4","license":"Apache-2.0","_id":"@dawnswwwww/open-security@0.1.4","maintainers":[{"name":"dawnswwwww","email":"wxn_em@163.com"}],"homepage":"https://github.com/dawnswwwww/open-security#readme","bugs":{"url":"https://github.com/dawnswwwww/open-security/issues"},"bin":{"open-security":"dist/cli.js"},"dist":{"shasum":"2cd9cd304ad341fac54203c1e878b1399e2ffa06","tarball":"https://registry.npmjs.org/@dawnswwwww/open-security/-/open-security-0.1.4.tgz","fileCount":76,"integrity":"sha512-5sHX8HDbUhNPbCmZiweqX2akTxCJfMEaN3ym9E6EdPmuxWQQAI33wucm3oiETOIVp9kOunBTIb2z2zv+dAM0iA==","signatures":[{"sig":"MEQCIBHWzE2BfCwx+5L4bXAH4lHvxFTl9fNi+dyYo/2+P2UgAiAdJgWZUwiJlzCs+xZJu9ZvFUC/PS1JXym1YjZEbgIX4w==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@dawnswwwww%2fopen-security@0.1.4","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":232336},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"cb6564a5cb8c66c7bdb9163e01de5ff2b9408a67","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc -p tsconfig.json","prepublishOnly":"npm run build"},"_npmUser":{"name":"dawnswwwww","email":"wxn_em@163.com"},"repository":{"url":"git+https://github.com/dawnswwwww/open-security.git","type":"git"},"_npmVersion":"10.9.8","description":"LLM-driven security diff scanner with a pluggable agent runtime (Claude Agent SDK by default, ACP-compatible agents supported)","directories":{},"_nodeVersion":"22.23.2","dependencies":{"zod":"^3.24.0","commander":"^13.0.0","@agentclientprotocol/sdk":"^1.3.0","@anthropic-ai/claude-agent-sdk":"^0.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.10.0"},"_npmOperationalInternal":{"tmp":"tmp/open-security_0.1.4_1786699837607_0.6447514450362002","host":"s3://npm-registry-packages-npm-production"}},"0.1.5":{"name":"@dawnswwwww/open-security","version":"0.1.5","license":"Apache-2.0","_id":"@dawnswwwww/open-security@0.1.5","maintainers":[{"name":"dawnswwwww","email":"wxn_em@163.com"}],"homepage":"https://github.com/dawnswwwww/open-security#readme","bugs":{"url":"https://github.com/dawnswwwww/open-security/issues"},"bin":{"open-security":"dist/cli.js"},"dist":{"shasum":"7d5f6590e2bb6c8f446f73f9d5a4df63770302ee","tarball":"https://registry.npmjs.org/@dawnswwwww/open-security/-/open-security-0.1.5.tgz","fileCount":76,"integrity":"sha512-CTH2qb0dNA8ecs+GZvnnRMsWtJtf3DWbO1z85guny6oAUxzmnPSoa/ejrqS1E2rueNyUm8RC2k0G5wXS0OAt5g==","signatures":[{"sig":"MEYCIQCFkTMZTlr0ce6pTwCJ0WLVrNDRIOUWbmOJUUoTFoGvewIhALSpNp3lk+bXHYiwT8pIb6LLWuebiYlgFqgVPSGmyfsb","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@dawnswwwww%2fopen-security@0.1.5","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":234308},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"3c3e105735eba952d82bc993c03503d1f9e6f88a","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc -p tsconfig.json","prepublishOnly":"npm run build"},"_npmUser":{"name":"dawnswwwww","email":"wxn_em@163.com"},"repository":{"url":"git+https://github.com/dawnswwwww/open-security.git","type":"git"},"_npmVersion":"10.9.8","description":"LLM-driven security diff scanner with a pluggable agent runtime (Claude Agent SDK by default, ACP-compatible agents supported)","directories":{},"_nodeVersion":"22.23.2","dependencies":{"zod":"^3.24.0","commander":"^13.0.0","@agentclientprotocol/sdk":"^1.3.0","@anthropic-ai/claude-agent-sdk":"^0.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.10.0"},"_npmOperationalInternal":{"tmp":"tmp/open-security_0.1.5_1786718075916_0.038630055170722155","host":"s3://npm-registry-packages-npm-production"}},"0.1.6":{"name":"@dawnswwwww/open-security","version":"0.1.6","license":"Apache-2.0","_id":"@dawnswwwww/open-security@0.1.6","maintainers":[{"name":"dawnswwwww","email":"wxn_em@163.com"}],"homepage":"https://github.com/dawnswwwww/open-security#readme","bugs":{"url":"https://github.com/dawnswwwww/open-security/issues"},"bin":{"open-security":"dist/cli.js"},"dist":{"shasum":"0183b4b9d89da3d84a9d9f5e575f9cb21c499953","tarball":"https://registry.npmjs.org/@dawnswwwww/open-security/-/open-security-0.1.6.tgz","fileCount":76,"integrity":"sha512-5T43LZ8m5Vvzn3F3+BxbWBCFaMekMkvh5VxT4vGWaYFxQNZWJ0HhuDrSWFgo6fjLrVnbG2ObTh7ZJjO+5QiMCw==","signatures":[{"sig":"MEUCIFVHigYMC/uzdYR7Zlosi1Fj+EOXwBUBalD1mR02zgFXAiEAvuBOMkoq5e/MQz1pqb4dECLnk5kFS9SVJFSO8s25BbE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@dawnswwwww%2fopen-security@0.1.6","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":257443},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"b0ee85c36fb548f45151a7f1833797f4c6d9c5a9","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc -p tsconfig.json","prepublishOnly":"npm run build"},"_npmUser":{"name":"dawnswwwww","email":"wxn_em@163.com"},"repository":{"url":"git+https://github.com/dawnswwwww/open-security.git","type":"git"},"_npmVersion":"10.9.8","description":"LLM-driven security diff scanner with a pluggable agent runtime (Claude Agent SDK by default, ACP-compatible agents supported)","directories":{},"_nodeVersion":"22.23.2","dependencies":{"zod":"^3.24.0","commander":"^13.0.0","@agentclientprotocol/sdk":"^1.3.0","@anthropic-ai/claude-agent-sdk":"^0.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.10.0"},"_npmOperationalInternal":{"tmp":"tmp/open-security_0.1.6_1786719201371_0.7452834159306763","host":"s3://npm-registry-packages-npm-production"}},"0.1.7":{"name":"@dawnswwwww/open-security","version":"0.1.7","license":"Apache-2.0","_id":"@dawnswwwww/open-security@0.1.7","maintainers":[{"name":"dawnswwwww","email":"wxn_em@163.com"}],"homepage":"https://github.com/dawnswwwww/open-security#readme","bugs":{"url":"https://github.com/dawnswwwww/open-security/issues"},"bin":{"open-security":"dist/cli.js"},"dist":{"shasum":"58a641d59e773e9ec0402ad90a92164cd2a9f093","tarball":"https://registry.npmjs.org/@dawnswwwww/open-security/-/open-security-0.1.7.tgz","fileCount":76,"integrity":"sha512-HACXq2/3E+rW1gYlhObftJGM6i9Mmm8YaelxmQ0qcAjesgjNrvoC2vW2YK5dG5D5SbMOB91wLYgg0swQcAJKeA==","signatures":[{"sig":"MEQCIEYxW7bKoSLSfqtwuopK6YhUjtvz3jjXneyW/1x7lPDzAiA0lU/vMjGHiv+VP8EvW8/Snh6II4knMSNCIavCcJTfJA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@dawnswwwww%2fopen-security@0.1.7","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":261341},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"aaf33bdde6987aa7f54251115c61775079e6c13f","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc -p tsconfig.json","prepublishOnly":"npm run build"},"_npmUser":{"name":"dawnswwwww","email":"wxn_em@163.com"},"repository":{"url":"git+https://github.com/dawnswwwww/open-security.git","type":"git"},"_npmVersion":"10.9.8","description":"LLM-driven security diff scanner with a pluggable agent runtime (Claude Agent SDK by default, ACP-compatible agents supported)","directories":{},"_nodeVersion":"22.23.2","dependencies":{"zod":"^3.24.0","commander":"^13.0.0","@agentclientprotocol/sdk":"^1.3.0","@anthropic-ai/claude-agent-sdk":"^0.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.10.0"},"_npmOperationalInternal":{"tmp":"tmp/open-security_0.1.7_1786721504000_0.5970920631084062","host":"s3://npm-registry-packages-npm-production"}},"0.1.8":{"name":"@dawnswwwww/open-security","version":"0.1.8","license":"Apache-2.0","_id":"@dawnswwwww/open-security@0.1.8","maintainers":[{"name":"dawnswwwww","email":"wxn_em@163.com"}],"homepage":"https://github.com/dawnswwwww/open-security#readme","bugs":{"url":"https://github.com/dawnswwwww/open-security/issues"},"bin":{"open-security":"dist/cli.js"},"dist":{"shasum":"76892c50e0a081dcd0a3e53e22cebd799237d3aa","tarball":"https://registry.npmjs.org/@dawnswwwww/open-security/-/open-security-0.1.8.tgz","fileCount":76,"integrity":"sha512-vg9wp750T6dvViIDK218EnYIge6z/GKpmT0QbGJyNC+Z3/xJb1SpukTCBPi3B1UDi3tpyec21pWsbm4v/GWNUw==","signatures":[{"sig":"MEUCIQDOqrfgUAJGqerxqLPrGsAuwYRdkdqe7zPhNC6RnY0jvQIgaZW0cMxpWXpvQaQSBjm4U4s8vY3hUrXBV35jj05sqMo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@dawnswwwww%2fopen-security@0.1.8","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":263729},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"29c39677a5dc65f1ec535e0554a7dcaea043f0d3","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc -p tsconfig.json","prepublishOnly":"npm run build"},"_npmUser":{"name":"dawnswwwww","email":"wxn_em@163.com"},"repository":{"url":"git+https://github.com/dawnswwwww/open-security.git","type":"git"},"_npmVersion":"10.9.8","description":"LLM-driven security diff scanner with a pluggable agent runtime (Claude Agent SDK by default, ACP-compatible agents supported)","directories":{},"_nodeVersion":"22.23.2","dependencies":{"zod":"^3.24.0","commander":"^13.0.0","@agentclientprotocol/sdk":"^1.3.0","@anthropic-ai/claude-agent-sdk":"^0.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.10.0"},"_npmOperationalInternal":{"tmp":"tmp/open-security_0.1.8_1786722226289_0.9003915901862991","host":"s3://npm-registry-packages-npm-production"}},"0.1.9":{"name":"@dawnswwwww/open-security","version":"0.1.9","license":"Apache-2.0","_id":"@dawnswwwww/open-security@0.1.9","maintainers":[{"name":"dawnswwwww","email":"wxn_em@163.com"}],"homepage":"https://github.com/dawnswwwww/open-security#readme","bugs":{"url":"https://github.com/dawnswwwww/open-security/issues"},"bin":{"open-security":"dist/cli.js"},"dist":{"shasum":"a42107c305ea08ea734645cef636dfd714e5f776","tarball":"https://registry.npmjs.org/@dawnswwwww/open-security/-/open-security-0.1.9.tgz","fileCount":79,"integrity":"sha512-3O9+ZmQmKemtVkbEM3Y24qMgQGG+CyPi3lZfn0NBfvijZl4n0DQv2++BwI6kwAdrZvjtk+CAd/tSbxm+/3ETkA==","signatures":[{"sig":"MEUCIBos+JTNpKhKt75abbdId54JSCQEYI6GZvx6LrGCbpTKAiEA+EWO6JwnUnSp0Zqg8Zfx0qsTfrc4GhHOSZy0kdbHxXo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@dawnswwwww%2fopen-security@0.1.9","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":273705},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"11ce4e4be092cb1188a55936fc0fc9120b0f1d68","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc -p tsconfig.json","prepublishOnly":"npm run build"},"_npmUser":{"name":"dawnswwwww","email":"wxn_em@163.com"},"repository":{"url":"git+https://github.com/dawnswwwww/open-security.git","type":"git"},"_npmVersion":"10.9.8","description":"LLM-driven security diff scanner with a pluggable agent runtime (Claude Agent SDK by default, ACP-compatible agents supported)","directories":{},"_nodeVersion":"22.23.2","dependencies":{"zod":"^3.24.0","commander":"^13.0.0","@agentclientprotocol/sdk":"^1.3.0","@anthropic-ai/claude-agent-sdk":"^0.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.10.0"},"_npmOperationalInternal":{"tmp":"tmp/open-security_0.1.9_1786930636174_0.7186165283232158","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@dawnswwwww/open-security","version":"0.2.0","license":"Apache-2.0","_id":"@dawnswwwww/open-security@0.2.0","maintainers":[{"name":"dawnswwwww","email":"wxn_em@163.com"}],"homepage":"https://github.com/dawnswwwww/open-security#readme","bugs":{"url":"https://github.com/dawnswwwww/open-security/issues"},"bin":{"open-security":"dist/cli.js"},"dist":{"shasum":"233229f64632c7affa83913152ce34c4a532123c","tarball":"https://registry.npmjs.org/@dawnswwwww/open-security/-/open-security-0.2.0.tgz","fileCount":85,"integrity":"sha512-8U1mflHAUBOwwG4dBSUNAek7nlsGhJyW+a3VzrkGPqcYdyyy9SlSG2OtTbkpsbZV59VTrwSRkuQqodBblOn2Hg==","signatures":[{"sig":"MEUCIQDZ13Gk3S6lL1A9dmkwF/jrnbd5OLCU5t+iDe4xaFug7AIgaoggAYvM0/qsBtiDCkNcJKPqK1plPotOdrNkrpt6gKM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@dawnswwwww%2fopen-security@0.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":331123},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"bfa2887009634a5dcc379e5ee20f783b6c05f2a5","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc -p tsconfig.json","prepublishOnly":"npm run build"},"_npmUser":{"name":"dawnswwwww","email":"wxn_em@163.com"},"repository":{"url":"git+https://github.com/dawnswwwww/open-security.git","type":"git"},"_npmVersion":"10.9.8","description":"LLM-driven security diff scanner with a pluggable agent runtime (Claude Agent SDK by default, OpenAI-compatible endpoints and ACP agents supported)","directories":{},"_nodeVersion":"22.23.2","dependencies":{"zod":"^3.24.0","commander":"^13.0.0","@mariozechner/pi-ai":"^0.73.1","@agentclientprotocol/sdk":"^1.3.0","@mariozechner/pi-coding-agent":"^0.73.1","@anthropic-ai/claude-agent-sdk":"^0.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.10.0"},"_npmOperationalInternal":{"tmp":"tmp/open-security_0.2.0_1786955455456_0.3485496331967557","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"@dawnswwwww/open-security","version":"0.2.1","license":"Apache-2.0","_id":"@dawnswwwww/open-security@0.2.1","maintainers":[{"name":"dawnswwwww","email":"wxn_em@163.com"}],"homepage":"https://github.com/dawnswwwww/open-security#readme","bugs":{"url":"https://github.com/dawnswwwww/open-security/issues"},"bin":{"open-security":"dist/cli.js"},"dist":{"shasum":"dc0178a37997b1c012e98a77bfd32f72adfed602","tarball":"https://registry.npmjs.org/@dawnswwwww/open-security/-/open-security-0.2.1.tgz","fileCount":85,"integrity":"sha512-bILmFkJD4nSEsWErp68W5U4jy93c9BB8Wsr3BVBsJ8uVG8EEEyi6sC5Dxmrab6ghWshIItXbsAGH628+CLfe5g==","signatures":[{"sig":"MEUCIEpU8nba+CFs60ua70BnedWsNMNEEBI7OZB4/WmJd5VSAiEAyD1NXQFQCfJ62Mf+8ZxT5kqMuFY6xHrbOsVo78gtNuQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@dawnswwwww%2fopen-security@0.2.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":332486},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"ee6cb2bbc382821048fbe3083c4e479cbc8b24ca","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc -p tsconfig.json","prepublishOnly":"npm run build"},"_npmUser":{"name":"dawnswwwww","email":"wxn_em@163.com"},"repository":{"url":"git+https://github.com/dawnswwwww/open-security.git","type":"git"},"_npmVersion":"10.9.8","description":"LLM-driven security diff scanner with a pluggable agent runtime (Claude Agent SDK by default, OpenAI-compatible endpoints and ACP agents supported)","directories":{},"_nodeVersion":"22.23.2","dependencies":{"zod":"^3.24.0","commander":"^13.0.0","@mariozechner/pi-ai":"^0.73.1","@agentclientprotocol/sdk":"^1.3.0","@mariozechner/pi-coding-agent":"^0.73.1","@anthropic-ai/claude-agent-sdk":"^0.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.10.0"},"_npmOperationalInternal":{"tmp":"tmp/open-security_0.2.1_1786955789135_0.6007785173279512","host":"s3://npm-registry-packages-npm-production"}},"0.2.2":{"name":"@dawnswwwww/open-security","version":"0.2.2","description":"LLM-driven security diff scanner with a pluggable agent runtime (pi agent by default for OpenAI-compatible and Anthropic endpoints; ACP agents supported)","license":"Apache-2.0","repository":{"type":"git","url":"git+https://github.com/dawnswwwww/open-security.git"},"bugs":{"url":"https://github.com/dawnswwwww/open-security/issues"},"homepage":"https://github.com/dawnswwwww/open-security#readme","type":"module","engines":{"node":">=22"},"bin":{"open-security":"dist/cli.js"},"main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"build":"tsc -p tsconfig.json","lint":"tsc --noEmit","test":"vitest run","prepublishOnly":"npm run build"},"dependencies":{"@agentclientprotocol/sdk":"^1.3.0","@mariozechner/pi-ai":"^0.73.1","@mariozechner/pi-coding-agent":"^0.73.1","commander":"^13.0.0","zod":"^3.24.0"},"devDependencies":{"@types/node":"^22.10.0","typescript":"^5.7.0","vitest":"^3.0.0"},"_id":"@dawnswwwww/open-security@0.2.2","gitHead":"04741caf5626a6cc78124aa432a029b848bae610","_nodeVersion":"22.23.2","_npmVersion":"10.9.8","dist":{"integrity":"sha512-zXH4wBdBoubWe1bcljFghHrfqpXo6KqoNMT9TUcpowXoTJKsUC8mmmBi0qw478cbN4orBjez4Oa/FxBz5niCFQ==","shasum":"2bc6dd4412e4830f7bf74d5460e1e816cff6d747","tarball":"https://registry.npmjs.org/@dawnswwwww/open-security/-/open-security-0.2.2.tgz","fileCount":88,"unpackedSize":338752,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@dawnswwwww%2fopen-security@0.2.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIF0zNiQff613CmbStOxJPJbWlVYa12ofKgLZrArhD++dAiEAtcgQM/+uEaU9uLNOLWt3PrqYjfSStCPqadUQyq/JM9E="}]},"_npmUser":{"name":"dawnswwwww","email":"wxn_em@163.com"},"directories":{},"maintainers":[{"name":"dawnswwwww","email":"wxn_em@163.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/open-security_0.2.2_1787024867556_0.21663322613039426"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-14T08:55:22.835Z","modified":"2026-08-18T03:47:48.055Z","0.1.0":"2026-08-14T08:55:23.155Z","0.1.1":"2026-08-14T09:10:41.269Z","0.1.2":"2026-08-14T09:24:20.070Z","0.1.3":"2026-08-14T09:26:15.896Z","0.1.4":"2026-08-14T09:30:37.765Z","0.1.5":"2026-08-14T14:34:36.073Z","0.1.6":"2026-08-14T14:53:21.522Z","0.1.7":"2026-08-14T15:31:44.161Z","0.1.8":"2026-08-14T15:43:46.466Z","0.1.9":"2026-08-17T01:37:16.324Z","0.2.0":"2026-08-17T08:30:55.612Z","0.2.1":"2026-08-17T08:36:29.277Z","0.2.2":"2026-08-18T03:47:47.739Z"},"bugs":{"url":"https://github.com/dawnswwwww/open-security/issues"},"license":"Apache-2.0","homepage":"https://github.com/dawnswwwww/open-security#readme","repository":{"type":"git","url":"git+https://github.com/dawnswwwww/open-security.git"},"description":"LLM-driven security diff scanner with a pluggable agent runtime (pi agent by default for OpenAI-compatible and Anthropic endpoints; ACP agents supported)","maintainers":[{"name":"dawnswwwww","email":"wxn_em@163.com"}],"readme":"# open-security\n\nLLM-driven security diff scanner. Reviews a Git diff the way a security\nengineer would — threat model, candidate discovery, independent validation,\nmechanical severity calibration — and emits a structured findings contract,\na human report, and SARIF for CI.\n\n- **CLI + SDK**: `open-security scan` or `new OpenSecurity().scanDiff()`.\n- **Pluggable agent runtime**: the default `pi` runtime embeds the pi agent\n  loop and runs any OpenAI-compatible or Anthropic endpoint (zero-config\n  against `https://api.anthropic.com`); `acp` accepts any ACP agent; inject\n  your own runtime through the SDK for other executors.\n- **Methodology over vibes**: discovery must cite source evidence; validation\n  requires counterevidence to reject; severity is calibrated by a mechanical\n  matrix in code, not re-argued by the model.\n- **Honest coverage**: complete means every changed file was actually\n  reviewed; deferred work is reported, never hidden.\n\n## Security scan methodology\n\nAdapted from the Codex Security plugin (Apache-2.0, see NOTICE):\n\n1. **Inventory** — deterministic changed-file list (deleted files kept,\n   dependency/build/test directories excluded).\n2. **Threat model** — repository-wide model, cached per revision, reused\n   across scans.\n3. **Discovery** — candidates grounded in the actual diff with\n   source/sink/control anchors; anti-hallucination rules enforced in the\n   prompt.\n4. **Validation** — each candidate gets a fresh session; rejection requires\n   source-backed counterevidence; proof gaps are recorded, never papered\n   over.\n5. **Severity** — impact × likelihood matrix plus hard suppression rules,\n   applied mechanically in TypeScript.\n6. **Contract** — `findings.json`, `scan-manifest.json`, `coverage.json`,\n   `report.md`, and SARIF 2.1.0 with stable fingerprints. A `usage.json`\n   artifact and a stderr report close the scan with per-phase token, cost,\n   turn, and duration accounting.\n\n## CLI\n\nTwo scan modes: **diff scan** (review a change set, the CI gate) and\n**repository scan** (ranked whole-repo review — omit `--base`).\n\n```bash\n# Zero-config diff scan against the Anthropic endpoint\n# (defaults: --runtime pi --base-url https://api.anthropic.com\n#  --api anthropic-messages --model claude-sonnet-4-5\n#  --api-key-env ANTHROPIC_API_KEY):\nexport ANTHROPIC_API_KEY=sk-ant-...\nopen-security scan . --base origin/main --fail-on-severity high\n\n# Repository-wide scan: works on Git repositories AND plain directories.\n# Files are ranked by security relevance (auth, crypto, SQL, parsers, ...),\n# top 150 deep-reviewed in batches, the rest honestly reported as deferred.\n# Non-Git targets get a directory_snapshot identity (content digest).\nopen-security scan . --max-files 150\n\n# Diff scan via any OpenAI-compatible endpoint:\nopen-security scan . \\\n  --base origin/main \\\n  --base-url https://llm-gateway.internal/v1 \\\n  --api-key-env INTERNAL_LLM_KEY \\\n  --model my-model \\\n  --fail-on-severity high \\\n  --output-dir out/\n```\n\nNotes:\n\n- The agent runs with read-only tools (`read_file`, `glob_files`,\n  `search_files`, `git_show`) — the scanner never modifies the repository\n  under review.\n- After every scan the CLI prints a usage report to stderr (total wall time,\n  agent runs, input/output/cache tokens, plus per-phase breakdown; a cached\n  threat model is marked `cached`), and writes the same numbers to\n  `usage.json` in the output directory. `pi` reports tokens and cache tokens\n  (gateway pricing is unknown to it); `acp` reports only run counts and\n  durations.\n- Exit code 1 when a finding meets `--fail-on-severity`; exit code 2 on\n  operational errors. `--json` prints a machine-readable summary.\n\n### ACP runtime\n\nAny Agent Client Protocol agent works as the executor. The agent process is\nlaunched fresh per pipeline phase (session isolation), model routing belongs\nto the agent's own configuration, and open-security enforces a read-only tool\npolicy (only `read`, `search`, and `think` tool kinds are approved):\n\n```bash\nopen-security scan . --base origin/main \\\n  --runtime acp --acp-command \"claude-code-acp\"\n```\n\n### pi runtime (default; OpenAI-compatible and Anthropic endpoints)\n\nThe `pi` runtime embeds the [pi](https://github.com/earendil-works/pi) agent\nloop in-process and routes it at any OpenAI Chat Completions-compatible\nendpoint — OpenAI, DeepSeek, Kimi, Qwen, OpenRouter, vLLM, Ollama (`/v1`),\nLiteLLM, or an internal gateway — and equally at Anthropic Messages\nendpoints. One runtime covers both wire protocols:\n\n```bash\n# Bare invocation: Anthropic defaults apply (anthropic-messages protocol,\n# claude-sonnet-4-5, key from ANTHROPIC_API_KEY):\nexport ANTHROPIC_API_KEY=sk-ant-...\nopen-security scan . --base origin/main\n\n# OpenAI-compatible endpoint (protocol inferred from --base-url):\nopen-security scan . --base origin/main \\\n  --base-url https://api.deepseek.com/v1 \\\n  --api-key-env DEEPSEEK_API_KEY \\\n  --model deepseek-chat\n\n# Anthropic-style gateway with an explicit model:\nopen-security scan . --base origin/main \\\n  --base-url https://claude-gateway.internal \\\n  --api-key-env GATEWAY_KEY \\\n  --model claude-sonnet-4-5\n```\n\nRule set when flags are omitted:\n\n- Runtime defaults to `pi` (`acp` requires `--runtime acp`).\n- Bare invocations (no `--base-url`) run against\n  `https://api.anthropic.com` with `--api anthropic-messages`, `--model\n  claude-sonnet-4-5`, and the key from `ANTHROPIC_API_KEY`.\n- Wire protocol (`--api`) is inferred from `--base-url`:\n  Anthropic-looking URLs get `anthropic-messages`, everything else\n  `openai-completions`. An explicit `--api` always wins.\n- `--model` is required whenever `--base-url` is passed explicitly.\n\nRead-only policy is enforced by construction: pi's built-in tools (bash,\nedit, write) are disabled and the only registered tools are open-security's\nown inspection tools (`read_file`, `glob_files`, `search_files`, `git_show`),\nall confined to the repository root. Sessions are in-memory and the pi config\ndirectory is a throwaway temp dir — nothing is written into the scanned\nrepository and no user-level pi settings, skills, or credentials leak in.\n\nModel choice is the main quality lever for this runtime: the workload needs\nlong context and reliable tool calling, so pick models known for both (for\nexample DeepSeek-V3.x, Kimi k2, GPT-class or Claude models). Small\nlocally-served models without solid tool-calling will underperform.\n\n### Quality benchmark\n\nMeasure recall and precision against repositories with known ground-truth\nfindings before trusting the scanner as a CI gate:\n\n```bash\nopen-security benchmark suite.json --output-dir benchmark-out/ \\\n  --base-url https://llm-gateway.internal/v1 \\\n  --api-key-env INTERNAL_LLM_KEY --model my-model\n```\n\n`suite.json` lists cases (repository, diff refs) plus expected findings\n(category + path, optional minimum severity); see\n`tests/fixtures/benchmark-suite.example.json`. The report lands in\n`benchmark-out/benchmark-report.json`. Harness mechanics are covered by the\ntest suite with a mock runtime; the quality numbers themselves depend on your\nmodel and prompts — run them against your internal endpoint first.\n\n## Install\n\n```bash\nnpm install @dawnswwwww/open-security\nnpx @dawnswwwww/open-security --help\n```\n\nThe CLI command is `open-security` regardless of the scoped package name.\n\n## SDK\n\n```ts\nimport { OpenSecurity } from \"@dawnswwwww/open-security\";\n\nconst scanner = new OpenSecurity({\n  runtime: {\n    runtime: \"pi\",\n    baseUrl: \"https://llm-gateway.internal/v1\",\n    model: \"my-model\",\n    apiKeyEnv: \"INTERNAL_LLM_KEY\",\n  },\n});\n\nconst result = await scanner.scanDiff(\".\", {\n  base: \"origin/main\",\n  failOnSeverity: \"high\",\n});\nconsole.log(result.reportPath, result.maxSeverity);\n```\n\nCustom executors (ACP agents, direct API loops) plug in via the `agent`\ninjection point:\n\n```ts\nconst scanner = new OpenSecurity({\n  runtime: { runtime: \"pi\", baseUrl: \"https://unit.test/v1\", model: \"m\", maxTurnsPerPhase: 400 }, // config is inert when agent is injected\n  agent: myRuntime, // implements AgentRuntime\n});\n```\n\n## Development\n\n```bash\nnpm install\nnpm run lint    # tsc --noEmit\nnpm test        # vitest\nnpm run build\n```\n\nTests run the full pipeline against a fixture Git repository with a mock\nagent runtime — no model access required.\n\n## License\n\nApache-2.0. Methodology and contract structures adapted from\nopenai/codex-security (Apache-2.0); see NOTICE.\n","readmeFilename":"README.md"}