{"_id":"vuln-vects","_rev":"2-c71ef9d9bdd1ce5ab6c3fdfa750cbcf4","name":"vuln-vects","dist-tags":{"latest":"1.1.0"},"versions":{"1.0.0":{"name":"vuln-vects","version":"1.0.0","description":"A powerful, flexible CVSS parser, calculator and validator written for JavaScript/TypeScript.","main":"./dist/index.js","types":"./dist/index.d.ts","scripts":{"build":"tsc --build","test":"mocha -r ts-node/register **/test/**/*.test.ts","bundle":"webpack","docs":"typedoc src/index.ts src/*-enums.ts --out docs/api"},"repository":{"type":"git","url":"git+https://github.com/security-breachlock/vuln-vects.git"},"keywords":["typescript","cvss","common","vulnerability","scoring","system","security","cyber"],"author":{"name":"BreachLock Inc.","email":"security@breachlock.com"},"license":"MIT","bugs":{"url":"https://github.com/security-breachlock/vuln-vects/issues"},"homepage":"https://github.com/security-breachlock/vuln-vects#readme","devDependencies":{"@types/chai":"^4.2.21","@types/mocha":"^9.0.0","@types/node":"^16.4.9","chai":"^4.3.4","mocha":"^9.0.3","ts-node":"^10.1.0","typedoc":"^0.21.5","typescript":"^4.3.5","webpack":"^5.47.1","webpack-cli":"^4.7.2"},"gitHead":"1f93b4df6e7de594b0ef80986f00b471cf4eec6d","_id":"vuln-vects@1.0.0","_nodeVersion":"14.17.3","_npmVersion":"6.14.13","dist":{"integrity":"sha512-3r8HBwXOc4iKB8VzMrsd5esSe/OigEIwwOlMAl1Dh0KA8Jc642c3LDdPZJ4Zs6PSenqDHefu9bCv1dfk9iUecg==","shasum":"e7c7ab5311838a44045c77bc4013dda94df147d5","tarball":"https://registry.npmjs.org/vuln-vects/-/vuln-vects-1.0.0.tgz","fileCount":111,"unpackedSize":1969450,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhB8CuCRA9TVsSAnZWagAA5LkP/ivKLR8tb7YXicYmPMC6\nRDqoJpd/0RUT1uozvLxw5vVaEG9eX+Rigu4VPwyA7dJVNnaG2EZlznumTaaQ\n+D2qrj8df1KaKX1LbvdaWp8sEZF10fMOy/PhPd9vgkpPPm5FyrlZ5pHFwwCa\nn3zsxoG4NdSPjIeEfd7nUmcX9uHTYNc+fgqyq5/mk5Zg9RWFSRCq69GtMcwQ\nasJG6FxyWtKMmvWA2LiqFufP37N3HxdzRW+EjWIPdg4cbsiveUd69Ty/WSrz\nRJBNhZUfW+khk2WpXfvyiV3GHiMGAR7+sbviMU5r682NyERFx7HChhZiDsLq\nD+lFjJbnt9QK4hfxVoSjUjEzHaRjmfxHRRFyMmU97VT/DT2OM9/3K3eWf4A+\nZuAnSKwlLZ+/Jo1DwG4i4XrTUJfLbVUnCiO63vhZQhNkrp1wt/g7PEx7Ps77\nJ3SVPxAVKpeeTrB+5khct0qBdkW35VFOiahl4Cl+A63cbvYK/g4gjaYP5dke\n6EDNjhdjcqRe+EqrQ8kl4k58fs6fupMx3r17sFGcav5cNij6NlnR5v1LnF/I\npaB5jZBTMPCW/vyzowUOjBUnkY+Hm27l/GeG9bDdAkmJwI9khBncEZ74hXPH\nX4AN+f6hsqndUMvCJNV4nArXQGHo5HIcxN2DMrw0kV2lHMPNW+clJE9TtJhi\nVAMb\r\n=/Lyu\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEMCH0rWdaVZKXrXtVdZBL98GDKjiPk6vxFS+kKdjMDVONoCIHju/Lc/EViuHR/2NLFqFLeo/4PUAOOMFZx9a3wkHQnd"}]},"_npmUser":{"name":"breachlock","email":"security@breachlock.com"},"directories":{},"maintainers":[{"name":"breachlock","email":"security@breachlock.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/vuln-vects_1.0.0_1627898029855_0.8086979363206475"},"_hasShrinkwrap":false},"1.1.0":{"name":"vuln-vects","version":"1.1.0","description":"A powerful, flexible CVSS parser, calculator and validator written for JavaScript/TypeScript.","main":"./dist/index.js","types":"./dist/index.d.ts","scripts":{"build":"tsc --build","test":"mocha -r ts-node/register **/test/**/*.test.ts","bundle":"webpack","docs":"typedoc src/index.ts src/*-enums.ts --out docs/api"},"repository":{"type":"git","url":"git+https://github.com/security-breachlock/vuln-vects.git"},"keywords":["typescript","cvss","common","vulnerability","scoring","system","security","cyber"],"author":{"name":"BreachLock Inc.","email":"security@breachlock.com"},"license":"MIT","bugs":{"url":"https://github.com/security-breachlock/vuln-vects/issues"},"homepage":"https://github.com/security-breachlock/vuln-vects#readme","devDependencies":{"@types/chai":"^4.2.21","@types/mocha":"^9.0.0","@types/node":"^16.4.9","chai":"^4.3.4","mocha":"^9.0.3","ts-node":"^10.1.0","typedoc":"^0.21.5","typescript":"^4.3.5","webpack":"^5.47.1","webpack-cli":"^4.7.2"},"gitHead":"e61c4bbd1b2236a9aa465ea2433448b1b5d08222","_id":"vuln-vects@1.1.0","_nodeVersion":"15.5.0","_npmVersion":"7.3.0","dist":{"integrity":"sha512-LGDwn9nRz94YoeqOn2TZqQXzyonBc5FJppSgH34S/1U+3bgPONq/vvfiCbCQ4MeBll58xx+kDmhS73ac+EHBBw==","shasum":"537d403615610446c1d687934584ea9dfb2a63ed","tarball":"https://registry.npmjs.org/vuln-vects/-/vuln-vects-1.1.0.tgz","fileCount":111,"unpackedSize":1966621,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCcei4u7FMBfm7M6iKiskDYyycuKedbBQ+QcsAwSZLm/QIgCHrvOICpNqWyR32V57hUDCeKuKxXm+ghypFEd/fcAxM="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJiuWqCACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoA3g//fXlMlIfoCwMpsSDxCXmpcUNV4e5qj/J4ah1/WWBlQq3VQR3B\r\nIe2uEfz4INA6/McScvKn8yu0yRp2yW3H8OfIExPJuRV970mBSlf8cgenWD8O\r\n76MBCnampyU+B2wPsC+0Y1hZn8oe4OPNrWL96IuX1Z+rxbj0d1sbhCHq+x3C\r\nlSUtFuFK58O4YZMOs8OqNO4hSDibM3T6uBViPfZ3AR2kEMIyvDECAwpMRDy2\r\nk802qC39cgN1yF4fYU6+Wix519ovPJm6/QzgAIc/0Ioie47RlY+59Mnwj6Ls\r\nt3XdvhmCnpO13dqIzM1Duat5Du/rt+CYtPOon4QAAIKa5mbvW++nog+lZwXl\r\nVUclIFRhixFCBEfEYOE52jviD6jtm7gMDLGIBX5wDEbvMPtAtF736xnNGF4r\r\nzRYyN8uXLi9DQvEKkvYAzCBLl3ZUPTyLXmlQkdL8RLP56n1DV2yCduu7oPdm\r\n3XOycCm1o2qZ2pW5Sy85cTaORp1gBY1y/5UZXOHOwvGIXOxtTxml1S5jps2o\r\nG5KBCm/ts2YNq7x8kYYJ3mktNMOUaVdT8F3S0Enf21uhVbTzlgaXbYVetKqD\r\ncRrKVSwDpw93pG6Hp/VgEhd0q1ZkTU/WnUv3847Jzq2JtKlrAWf5XSmyEpBw\r\nclup6RN8S2n+QoyeA2zWNiLMY4grH2eABkY=\r\n=cKQF\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"breachlock","email":"security@breachlock.com"},"directories":{},"maintainers":[{"name":"breachlock","email":"security@breachlock.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/vuln-vects_1.1.0_1656318594646_0.964456929835865"},"_hasShrinkwrap":false}},"time":{"created":"2021-08-02T09:53:49.855Z","1.0.0":"2021-08-02T09:53:50.073Z","modified":"2022-06-27T08:29:54.916Z","1.1.0":"2022-06-27T08:29:54.842Z"},"maintainers":[{"name":"breachlock","email":"security@breachlock.com"}],"description":"A powerful, flexible CVSS parser, calculator and validator written for JavaScript/TypeScript.","homepage":"https://github.com/security-breachlock/vuln-vects#readme","keywords":["typescript","cvss","common","vulnerability","scoring","system","security","cyber"],"repository":{"type":"git","url":"git+https://github.com/security-breachlock/vuln-vects.git"},"author":{"name":"BreachLock Inc.","email":"security@breachlock.com"},"bugs":{"url":"https://github.com/security-breachlock/vuln-vects/issues"},"license":"MIT","readme":"# Vuln/Vects\n\n![CI](https://github.com/security-breachlock/vuln-vects/actions/workflows/main.yml/badge.svg)\n\nA powerful, flexible CVSS parser, calculator and validator written for JavaScript/TypeScript.\n\n![Logo](logo-readme.svg)\n\n## Overview\nVuln/Vects is a library written in TypeScript, targeting JavaScript (server-side [Node.js](https://nodejs.org/en/) or\nbrowser) that aims to provide all the generation, validation, scoring and manipulation functionality you could ever need\nwhen working with CVSS (common vulnerability scoring system) vectors of any version. CVSS v2, v3.0 and v3.1 are\ncurrently supported.\n\n## Installing\nInstalling the project is very straightforward via [npm](https://www.npmjs.com/):\n\n```bash\nnpm install --save vuln-vects\n```\n\nIf you're working in TypeScript and need type annotations etc. you might also want to run:\n\n```bash\nnpm install --save @types/vuln-vects\n```\n\n## Building\nIt's only necessary to build the project if you're doing development work on it. There's no need to do so if you're just installing it to use as a library. Ensure that [Node.js v14.x](https://nodejs.org/en/) and npm is installed and run:\n\n```bash\nnpm run build\n```\n\nBuild output is to `/dist`. To build accompanying documentation, you need the following command:\n\n```bash\nnpm run docs\n```\n\nDocumentation is generated using [TypeDoc](https://typedoc.org/) and rendered as HTML to `/docs/api`.\n\n## Bundling\nYou'll need to bundle the library if you want to use it in-browser (remember to build it first):\n\n```bash\nnpm run build && npm run bundle\n```\n\nThis will give you a single file in `/bundle` that you can import into your webpages (see [Usage](#usage) section).\n\n## Running tests\nTests are on [Mocha](https://mochajs.org/) and [Chai](https://www.chaijs.com/). You can run them like so:\n\n```bash\nnpm run test\n```\n\n## Usage\nUsage of the library will vary, depending on whether you want to run in-browser or as part of a server-side Node.js project. In any case, you'll need to begin by installing the library:\n\n```bash\nnpm install --save vuln-vects\n```\n\nIf you want to do a deep dive on the functionality of the library, take a look at [the full API documentation](https://security-breachlock.github.io/vuln-vects/api).\n\n### In the browser\nUsage in the browser is super straightforward. After installation, simply import the bundled library into your webpage like so:\n\n```html\n<script src=\"node_modules/vuln-vects/bundle/vuln-vects.js\"></script>\n```\n\nYou'll then get a `VulnVects` object in the global namespace through which you can use the library:\n\n```html\n<script>\n    alert(VulnVects.parseCvss2Vector('CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N').baseScore); // Shows '5.0'.\n</script>\n```\n\n### On the server\nImporting and invoking the library is slightly different on the server side.\n\n```js\nimport { parseCvss2Vector } from 'vuln-vects';\n\nconsole.log(parseCvss2Vector('CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N').baseScore); // Prints '5.0'.\n```\n\nAside from this, the API is identical. There is a lot more you can do with the library aside from just the above. See [Features](#features) for more details.\n\n## Features\nThe library provides 4 main features: validation, scoring, rendering and mocking. If there's anything else you'd like to see, please consider opening an issue.\n\n### Validating\nValidation of CVSS vectors of any currently supported version is possible. Convenience methods offer the simplest API for this:\n\n```js\nimport {\n    validateCvss2Vector,\n    validateCvss3Vector,\n    validateCvssVector\n} from 'vuln-vects';\n\n// Will be true on validation success, false on failure.\nconst isValidCvss2Vector = validateCvss2Vector('(AV:N/AC:L/Au:N/C:P/I:N/A:N)'); // For CVSS v2.\nconst isValidCvss3Vector = validateCvss3Vector('AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'); // For CVSS v3.x.\nconst isValidCvssVector = validateCvssVector('AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'); // Version-agnostic.\n```\n\nValidation, in this context, means that CVSS vectors must be both well-formed and contain all required fields. If a CVSS vector is not well-formed (e.g. is missing separators as in `AV:NAC:LPR:NUI:NS:UC:NI:LA:N`) or does not contain all required fields to compute a score (e.g. does not contain a confidentiality impact as in `AV:N/AC:L/PR:N/UI:N/S:U/I:L/A:N`) validation will fail.\n\nTo get more detail about exactly why a vector failed validation, you can use the scoring API. For CVSS v2 vectors for example:\n\n```js\nimport {\n    Cvss2VectorParser\n} from 'vuln-vects';\n\nconst parser = new Cvss2VectorParser();\nconst scoringEngine = parser.generateScoringEngine('AV:N/AC:L/Au:N/C:P/I:N'); // Missing availability impact.\n\nconst isValid = scoringEngine.isValid(); // Will be true on validation success, false on failure.\nconst errors = scoringEngine.validate(); // Will return a list of human-readable validation errors.\n```\n\n### Scoring\nScoring CVSS vectors (i.e. converting them into a CVSS score from 1-10) is the most common use-case for the library, and as such has been designed to be very convenient to use via helper methods:\n\n```js\nimport {\n    parseCvss2Vector,\n    parseCvss3Vector,\n    parseCvssVector\n} from 'vuln-vects';\n\n// Will yield score objects.\nconst cvss2VectorScore = parseCvss2Vector('(AV:N/AC:L/Au:N/C:P/I:N/A:N)'); // For CVSS v2.\nconst cvss3VectorScore = parseCvss3Vector('AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'); // For CVSS v3.x.\nconst cvssVectorScore = parseCvssVector('AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'); // Version-agnostic.\n\n// The resulting score objects contain several subscores, but you probably want base score or overall score.\nconsole.log(cvss2VectorScore.baseScore);\nconsole.log(cvss2VectorScore.overallScore);\n```\n\n### Rendering\nRendering CVSS vectors refers to the process of generating CVSS vector strings from a set of metrics. This is a bit more involved, but still not especially complex:\n\n```js\nimport {\n    Cvss2ScoringEngine,\n    Cvss2VectorRenderer,\n    Cvss2VectorPrefixOption,\n    cvss2, // Enums specific to CVSS v2.\n} from 'vuln-vects';\n\n// Set up and configure a scoring engine.\nconst scoringEngine = new Cvss2ScoringEngine();\nscoringEngine.accessVector = cvss2.AccessVector.NETWORK;\nscoringEngine.accessComplexity = cvss2.AccessComplexity.MEDIUM;\nscoringEngine.authentication = cvss2.Authentication.NONE;\nscoringEngine.confidentialityImpact = cvss2.Impact.NONE;\nscoringEngine.integrityImpact = cvss2.AccessVector.COMPLETE;\nscoringEngine.availabilityImpact = cvss2.AccessVector.NONE;\n\n// Feed this to an appropriate vector renderer.\nconst vectorRenderer = new Cvss2VectorRenderer(Cvss2VectorPrefixOption.BRACKETED);\nconsole.log(vectorRenderer.render(scoringEngine));\n```\n\n### Mocking\nThe ability to randomly generate (i.e. mock) CVSS vectors for use in unit testing application that consume them can be very useful. Convenience methods are provided for this purpose:\n\n```js\nimport {\n    randomCvss2Vector,\n    randomCvss3Vector,\n    Cvss2VectorPrefixOption\n} from 'vuln-vects';\n\n// Shows a random CVSS v2 and v3.x vector.\nconsole.log(randomCvss2Vector());\nconsole.log(randomCvss3Vector());\n\n// Temporal/environmental scores and any valid prefixing scheme are supported:\nconsole.log(randomCvss2Vector(true, true, Cvss2VectorPrefixOption.BRACKETED));\n```\n\n## Acknowledgements\nThe main contributors to this project so far are as follows:\n\n* Saul Johnson ([@lambdacasserole](https://github.com/lambdacasserole))\n* Sai Srinivas ([@saikop99](https://github.com/saikop99))\n","readmeFilename":"README.md"}