{"_id":"@dhanush40/npm-guard","name":"@dhanush40/npm-guard","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@dhanush40/npm-guard","version":"1.0.0","description":"Unified dependency health and supply-chain risk scanner for npm projects","bin":{"npm-guard":"bin/npm-guard.js"},"homepage":"https://github.com/DhanushShettyH/npm-guard#readme","bugs":{"url":"https://github.com/DhanushShettyH/npm-guard/issues"},"repository":{"type":"git","url":"git+https://github.com/DhanushShettyH/npm-guard.git"},"license":"ISC","author":{"name":"Dhanush H"},"type":"module","main":"dist/index.js","exports":{".":{"import":"./dist/index.js","require":"./dist/index.cjs"}},"types":"dist/index.d.ts","scripts":{"build":"tsc","dev":"ts-node src/index.ts","lint":"eslint .","test":"vitest run || exit 0","prepublishOnly":"npm run build"},"engines":{"node":">=18"},"keywords":["security","npm","audit","supply-chain","deprecated","typosquatting","vulnerability","dependency","scanner","health-check"],"dependencies":{"chalk":"^5.3.0","commander":"^12.0.0","leven":"^4.0.0","ora":"^8.0.0","semver":"^7.6.0","undici":"^6.19.8"},"devDependencies":{"@types/node":"^22.0.0","@typescript-eslint/eslint-plugin":"^8.0.0","@typescript-eslint/parser":"^8.0.0","esbuild":"^0.23.0","eslint":"^9.0.0","ts-node":"^10.9.2","typescript":"^5.6.3","vitest":"^2.1.1"},"_id":"@dhanush40/npm-guard@1.0.0","gitHead":"70a682fde6255353c170844dbfe6663011221b12","_nodeVersion":"22.14.0","_npmVersion":"11.4.2","dist":{"integrity":"sha512-La4/iogerkDc6UHPPVJ5sz1mCn2xYkNEwa0EAR5AyUSXdRNhjsz87yJY2h1kyA6Ota7HW0cacBpLVf9XQbezXg==","shasum":"b201a05152bd932f5c35ce69486e97e0f201f7f3","tarball":"https://registry.npmjs.org/@dhanush40/npm-guard/-/npm-guard-1.0.0.tgz","fileCount":21,"unpackedSize":41534,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQD8AtUl9j4QCLe5IjvtTjnDq1WoVM3RBZ8dnF52+i5HewIgPRshSZ6CugA9oekAK1CKiO4yn2e/xR/kIOsutQE08j0="}]},"_npmUser":{"name":"dhanush40","email":"dhanushtruth@gmail.com"},"directories":{},"maintainers":[{"name":"dhanush40","email":"dhanushtruth@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/npm-guard_1.0.0_1759426768181_0.41313178162351427"},"_hasShrinkwrap":false}},"time":{"created":"2025-10-02T17:39:28.102Z","1.0.0":"2025-10-02T17:39:28.379Z","modified":"2025-10-02T17:39:28.639Z"},"maintainers":[{"name":"dhanush40","email":"dhanushtruth@gmail.com"}],"description":"Unified dependency health and supply-chain risk scanner for npm projects","homepage":"https://github.com/DhanushShettyH/npm-guard#readme","keywords":["security","npm","audit","supply-chain","deprecated","typosquatting","vulnerability","dependency","scanner","health-check"],"repository":{"type":"git","url":"git+https://github.com/DhanushShettyH/npm-guard.git"},"author":{"name":"Dhanush H"},"bugs":{"url":"https://github.com/DhanushShettyH/npm-guard/issues"},"license":"ISC","readme":"# npm-guard 🛡️\r\n\r\n> Unified dependency health and supply-chain risk scanner for npm projects\r\n\r\n[![npm version](https://img.shields.io/npm/v/npm-guard.svg)](https://www.npmjs.com/package/npm-guard)\r\n[![License: ISC](https://img.shields.io/badge/License-ISC-yellow.svg)](https://opensource.org/licenses/ISC)\r\n[![Node.js CI](https://github.com/yourusername/npm-guard/workflows/CI/badge.svg)](https://github.com/yourusername/npm-guard/actions)\r\n\r\n## Why npm-guard?\r\n\r\nModern npm projects face increasing supply chain risks. While tools like `npm audit` check for known vulnerabilities, they miss critical signals like:\r\n\r\n- 📦 **Deprecated packages** that may have security issues\r\n- 🎯 **Typosquatting risks** from packages with similar names\r\n- ⏰ **Fresh publishes** that haven't been vetted (<72h cooldown)\r\n- 📊 **Maintenance signals** like stale packages or low popularity\r\n- 🔍 **Holistic health scoring** across all risk factors\r\n\r\nnpm-guard provides a unified command to check all these risks at once.\r\n\r\n## Features\r\n\r\n✅ **Comprehensive Scanning**\r\n\r\n- Deprecated package detection with messages\r\n- Typosquatting and case-variant impersonation checks\r\n- Cooldown warnings for recently published versions\r\n- Maintenance signals (last publish, downloads, staleness)\r\n- npm audit vulnerability integration\r\n\r\n✅ **Actionable Output**\r\n\r\n- Health score (0-100) for your entire project\r\n- Per-package scoring and specific remediation advice\r\n- Human-friendly console output or JSON for CI/CD\r\n- Exit codes for CI gating\r\n\r\n✅ **Fast & Lightweight**\r\n\r\n- Zero runtime dependencies for scanning\r\n- Parallel fetching for speed\r\n- Works with existing npm/package-lock.json\r\n\r\n## Installation\r\n\r\n```bash\r\n# Run without installing (recommended)\r\nnpx npm-guard\r\n\r\n# Or install globally\r\nnpm install -g npm-guard\r\n\r\n# Or add to your project\r\nnpm install --save-dev npm-guard\r\n```\r\n\r\n## Quick Scan\r\n\r\n```bash\r\n# Scan current directory\r\nnpx npm-guardian\r\n\r\n# Output JSON for CI/CD\r\nnpx npm-guardian --json > report.json\r\n\r\n# Fail if health score < 70\r\nnpx npm-guardian --fail-under 70\r\n```\r\n\r\n## Example Output\r\n\r\n```\r\n═══ npm-guardian Report ═══\r\n\r\nOverall Health Score: 82/100\r\n──────────────────────────────────────────────────\r\n\r\n⚠ Deprecated packages: 1\r\n⚠ Typosquat risks: 1\r\n⏰ Recently published: 2\r\n\r\nVulnerabilities:\r\n  🔴 Critical: 0\r\n  🟠 High: 1\r\n  🟡 Moderate: 3\r\n  🔵 Low: 2\r\n\r\nPackage Details:\r\n──────────────────────────────────────────────────\r\n\r\nrequest@2.88.2\r\n  Score: 45/100\r\n  ⚠ DEPRECATED: request has been deprecated\r\n  📊 Weekly downloads: 25,341,234\r\n  📅 Last published: 4 years ago\r\n  Recommendations:\r\n    • Deprecated: request has been deprecated\r\n    • Not updated in 4 years. May be unmaintained.\r\n    • Consider migrating to: axios, node-fetch, or undici\r\n\r\nlodash.debounce@4.0.8\r\n  Score: 68/100\r\n  🎯 Typosquat medium: Similar to lodash\r\n  📊 Weekly downloads: 9,123,456\r\n  📅 Last published: 6 years ago\r\n```\r\n","readmeFilename":"README.md","_rev":"1-15bbddc0050081f3beec2bf712bdb3c6"}