{"_id":"@eimerreis/npm-compromise-scanner","_rev":"2-56092220f4056ce10e6aea7b1ce51323","name":"@eimerreis/npm-compromise-scanner","dist-tags":{"latest":"0.2.0"},"versions":{"0.1.0":{"name":"@eimerreis/npm-compromise-scanner","version":"0.1.0","keywords":["npm","security","supply-chain","malware","scanner","cli"],"author":{"name":"Moritz Frölich","email":"mail@moritzfroelich.de"},"license":"MIT","_id":"@eimerreis/npm-compromise-scanner@0.1.0","maintainers":[{"name":"eimerreis","email":"mail@moritzfroelich.de"}],"homepage":"https://github.com/eimerreis/npm-compromise-scanner#readme","bugs":{"url":"https://github.com/eimerreis/npm-compromise-scanner/issues"},"bin":{"npm-compromise-scan":"dist/bin.js"},"dist":{"shasum":"04c9264a1e7e7c2819f430eda6914f759c09ea81","tarball":"https://registry.npmjs.org/@eimerreis/npm-compromise-scanner/-/npm-compromise-scanner-0.1.0.tgz","fileCount":28,"integrity":"sha512-Fvit+G8l+QoHMq8sRdfnXfZGtgXb6Mhb4FadNHl29X2drGflzFUSzKUW+KBILCYktLBR2P+UnrcGYMGSC013/A==","signatures":[{"sig":"MEQCIEXAwqDuHzMEnhG3lI004VcMN0SrO3i/6Mk29a5FtKRwAiBm/oIGwZEqQdkUl65RURSt8E05JwjzfX+HomFQQsO1Cg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":58407},"type":"module","engines":{"node":">=20"},"exports":{".":"./dist/index.js"},"gitHead":"316d9c135e9a2f639482273bd8f13cd4037695e1","scripts":{"dev":"tsx src/bin.ts","test":"tsx --test","build":"tsc -p tsconfig.build.json","check":"tsc -p tsconfig.json --noEmit","prepack":"npm run build","release":"npm run build && changeset publish","changeset":"changeset","version-packages":"changeset version"},"_npmUser":{"name":"eimerreis","email":"mail@moritzfroelich.de"},"repository":{"url":"git+https://github.com/eimerreis/npm-compromise-scanner.git","type":"git"},"_npmVersion":"11.6.2","description":"Cross-platform CLI for finding known compromised npm package versions on a machine.","directories":{},"_nodeVersion":"24.12.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.23.7","typescript":"^7.0.2","@types/node":"^24.0.0","@changesets/cli":"^2.31.1"},"_npmOperationalInternal":{"tmp":"tmp/npm-compromise-scanner_0.1.0_1785914625961_0.05867405318216723","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@eimerreis/npm-compromise-scanner","version":"0.2.0","description":"Cross-platform CLI for finding known compromised npm package versions on a machine.","type":"module","author":{"name":"Moritz Frölich","email":"mail@moritzfroelich.de"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/eimerreis/npm-compromise-scanner.git"},"homepage":"https://github.com/eimerreis/npm-compromise-scanner#readme","bugs":{"url":"https://github.com/eimerreis/npm-compromise-scanner/issues"},"keywords":["npm","security","supply-chain","malware","scanner","cli"],"publishConfig":{"access":"public"},"bin":{"npm-compromise-scan":"dist/bin.js"},"exports":{".":"./dist/index.js"},"engines":{"node":">=20"},"scripts":{"build":"tsc -p tsconfig.build.json","changeset":"changeset","check":"tsc -p tsconfig.json --noEmit","dev":"tsx src/bin.ts","prepack":"npm run build","release":"npm run build && changeset publish","test":"tsx --test","version-packages":"changeset version"},"devDependencies":{"@changesets/cli":"^2.31.1","@types/node":"^24.0.0","tsx":"^4.23.7","typescript":"^7.0.2"},"gitHead":"a774f15641e34eb9a56aac10cdfa7cfcd7d60dd2","_id":"@eimerreis/npm-compromise-scanner@0.2.0","_nodeVersion":"24.18.0","_npmVersion":"11.19.0","dist":{"integrity":"sha512-MqBMWemOQIKJSHv0Ed96r7gcuItcdxRjBqWj1KoY57fGMnB/ji1HiBJcjs9rE9PAYph4eiJ/0kV6nSiGQB0xUg==","shasum":"9e385318ea61ea159933607c20e4b1c303345496","tarball":"https://registry.npmjs.org/@eimerreis/npm-compromise-scanner/-/npm-compromise-scanner-0.2.0.tgz","fileCount":28,"unpackedSize":76106,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@eimerreis%2fnpm-compromise-scanner@0.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCfl33wfTmr9b9SlGDdIMaCExhJiIcWo9CraEMhDmvsKgIhAOUgh2xvdEuXhXC7iip6rd9sGmouBNzRz/b03cHA6/Pz"}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:cdc76927-2c5b-44e7-90c7-ff872f90d375"}},"directories":{},"maintainers":[{"name":"eimerreis","email":"mail@moritzfroelich.de"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/npm-compromise-scanner_0.2.0_1785926385084_0.8093119615105919"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-05T07:23:45.731Z","modified":"2026-08-05T10:39:45.553Z","0.1.0":"2026-08-05T07:23:46.120Z","0.2.0":"2026-08-05T10:39:45.233Z"},"bugs":{"url":"https://github.com/eimerreis/npm-compromise-scanner/issues"},"author":{"name":"Moritz Frölich","email":"mail@moritzfroelich.de"},"license":"MIT","homepage":"https://github.com/eimerreis/npm-compromise-scanner#readme","keywords":["npm","security","supply-chain","malware","scanner","cli"],"repository":{"type":"git","url":"git+https://github.com/eimerreis/npm-compromise-scanner.git"},"description":"Cross-platform CLI for finding known compromised npm package versions on a machine.","maintainers":[{"name":"eimerreis","email":"mail@moritzfroelich.de"}],"readme":"# @eimerreis/npm-compromise-scanner\n\nCross-platform CLI that scans package manifests and npm, Yarn, pnpm, and Bun lockfiles for exact package/version pairs associated with npm supply-chain incidents.\n\n## Usage\n\n```bash\nnpx @eimerreis/npm-compromise-scanner\n```\n\nThe default scan root is `/` on macOS/Linux and the system drive on Windows. Full-machine scans may require an elevated shell.\n\n```bash\nsudo npx @eimerreis/npm-compromise-scanner\n```\n\nOptions:\n\n```text\n--root <path>        Scan a specific root\n--manifest <path>    Use a custom vulnerability manifest\n--cache-file <path>  Use a custom candidate inventory cache\n--no-cache           Disable the candidate inventory cache\n--clear-cache        Clear the cache before scanning\n-h, --help           Show help\n-v, --version        Show version\n```\n\n## Candidate cache\n\nThe first run discovers package manifests and lockfiles across the selected root and stores only their paths in the OS cache directory. Later runs scan those cached paths immediately while refreshing the filesystem inventory in parallel. Newly discovered files are scanned after discovery, and stale paths are removed from the cache.\n\nDefault cache locations:\n\n```text\nmacOS    ~/Library/Caches/npm-compromise-scanner/inventory.json\nLinux    $XDG_CACHE_HOME/npm-compromise-scanner/inventory.json\n         or ~/.cache/npm-compromise-scanner/inventory.json\nWindows  %LOCALAPPDATA%\\npm-compromise-scanner\\cache\\inventory.json\n```\n\n## Workspace Manifest\n\nCreate a local manifest interactively:\n\n```bash\nnpm-compromise-scan init\n```\n\nThis writes `./npm-compromise-scanner.json`. A scan run from that directory uses it instead of the bundled manifest. Use `--output <path>` to choose another location, and `--force` to replace an existing output file.\n\nCoding agents and scripts can create the same manifest without prompts after extracting exact pairs from an advisory:\n\n```bash\nnpm-compromise-scan init \\\n  --source https://example.com/advisory \\\n  --package keyv@6.0.0 \\\n  --package @cacheable/memory@2.2.1\n```\n\nRepeat `--package` for each affected pair. Scoped packages are supported.\n\n```bash\nnpm-compromise-scan --manifest ./other-manifest.json\n```\n\nAn explicit `--manifest` always takes precedence over the Workspace Manifest.\n\n## Custom manifest\n\n```json\n{\n  \"schemaVersion\": 1,\n  \"incidents\": [\n    {\n      \"id\": \"incident-id\",\n      \"source\": \"https://example.com/advisory\",\n      \"packages\": [\n        {\n          \"name\": \"package-name\",\n          \"versions\": [\"1.2.3\"]\n        }\n      ]\n    }\n  ]\n}\n```\n\n## Exit codes\n\n```text\n0  No configured compromised versions found\n1  At least one configured compromised version found\n2  Invalid input or an incomplete scan\n```\n\n## Development\n\nThe package uses Node.js at runtime, `tsx` for TypeScript development/tests, and `tsc` for publishing JavaScript. Bun is not required.\n\n```bash\nnpm install\nnpm test\nnpm run check\nnpm run build\nnpm run dev -- --root /path/to/scan\n```\n\n## Releasing\n\nRecord the release intent and push it to `main`:\n\n```bash\nnpm run changeset\ngit add .changeset\ngit commit -m \"chore: add release changeset\"\ngit push\n```\n\nThe release workflow verifies the package, applies the pending changeset, publishes through npm trusted publishing, commits the version update, and creates the corresponding GitHub release.\n","readmeFilename":"README.md"}