Node.js security CLI. The goal of the project is to a design a CLI (and a API) that will fetch and deeply analyze the dependency tree of a given npm package (or a local project) and output a .json file that will contains all metadata and flags about each packages.
The CLI will allow to load this .json to draw a Network of all dependencies in a webpage (example below).
Note: The TypeScript definition of the .json file can be found in the root file index.d.ts
- Node.js version 12 or higher
$ npm install nsecure -gor
$ git clone https://github.com/ES-Community/nsecure.git
$ cd nsecure
$ npm ci
$ npm linkTo show the complete list of commands
$ nsecure --help# Run analysis on the current working dir
$ nsecure cwd
# Run analysis for a given 'npm' package (must be in the registry).
$ nsecure from @sindresorhus/isThen a result.json will be writted at the current location. To view it on web page just run
$ nsecure httpSome options are available on both cwd and from commands.
| name | shortcut | default value | description |
|---|---|---|---|
| --depth | -d | 4 | the maximum depth we must walk (when we fetch the whole tree). |
| --output | -o | result | the name that the outputted .json file will have |
$ nsecure from express -d 10 -o express-security-reportNsecure allow you to fetch stats on private npm packages by setting up a NODE_SECURE_TOKEN env variable (which must contain a npm token).
Use nsecure as API package to fetch and work with the JSON. The following example demonstrate how to retrieve the JSON Payload for mocha, cacache and is-wsl packages. It's possible to use the cwd method if you want to achieve similar work on local projects.
const { from } = require("nsecure");
const { writeFile } = require("fs").promises;
async function main() {
const toFetch = ["mocha", "cacache", "is-wsl"];
const options = { verbose: false };
const payloads = await Promise.all(
toFetch.map((name) => from(name, options))
);
const toWritePromise = [];
for (let i = 0; i < toFetch.length; i++) {
const fileName = `${toFetch[i]}.json`;
const data = JSON.stringify(payloads[i], null, 2);
toWritePromise.push(writeFile(fileName, data));
}
await Promise.all(toWritePromise);
}
main().catch(console.error);| emoji | flag name | description |
|---|---|---|
| ☁️ | isGit | The package (project) is a git repository |
| 🌲 | hasIndirectDependencies | The package have indirect dependencies. |
| hasSuspectImport | The package have suspect import. | |
| ⛔️ | isDeprecated | The package has been tagged as deprecated |
| 📜 | hasLicense | The license is missing (or has not been detected) |
| 📚 | hasMultipleLicenses | The package has multiple licenses in multiple files. |
| 🔬 | hasMinifiedCode | The package has minified/uglified code |
| 💎 | hasCustomResolver | The package has at least one dependency that is not a npm package (like a git link or a local file link) |
| 🌍 | hasExternalCapacity | The package use at least one Node.js dependency capable to communicate outside or to establish a listening server |
| 📦 | hasScript | has post and/or pre (un)install npm script |
| 💕 | hasManyPublishers | The package has more than one publishers |
| 👥 | hasChangedAuthor | The package "author" field has been updated at least one time |
| 🚨 | vulnerabilities | The package have one or many vulnerabilities |
Note: hasManyPublishers and hasChangedAuthor are not flags linked to a given package version (but to the package itself).
Right now, vulnerabilities are not shipped automatically because it request a manual action to hydrate a local .json file with all detected vulnerabilities from the Security WG repository.
To run the hydratation just run the following command in your terminal:
$ nsecure hydrate-dbMIT
