Sitelet https://github.com/netcode/nsecure
Skip to content
netcodePublic
forked from NodeSecure/cli

About

Node.js security CLI / API that allow you to deeply analyze the dependency tree of a given package / directory

Resources

Stars

0 stars

Watchers

0 watching

Forks

 
 

Repository files navigation

node-secure

ver license build status Test coverage dep size

Node.js security CLI. The goal of the project is to a design a CLI (and a API) that will fetch and deeply analyze the dependency tree of a given npm package (or a local project) and output a .json file that will contains all metadata and flags about each packages.

The CLI will allow to load this .json to draw a Network of all dependencies in a webpage (example below).

Note: The TypeScript definition of the .json file can be found in the root file index.d.ts

Requirements

Getting Started

$ npm install nsecure -g

or

$ git clone https://github.com/ES-Community/nsecure.git
$ cd nsecure
$ npm ci
$ npm link

Usage example

To show the complete list of commands

$ nsecure --help

# Run analysis on the current working dir
$ nsecure cwd

# Run analysis for a given 'npm' package (must be in the registry).
$ nsecure from @sindresorhus/is

Then a result.json will be writted at the current location. To view it on web page just run

$ nsecure http

Some options are available on both cwd and from commands.

name shortcut default value description
--depth -d 4 the maximum depth we must walk (when we fetch the whole tree).
--output -o result the name that the outputted .json file will have
$ nsecure from express -d 10 -o express-security-report

Fetching private packages

Nsecure allow you to fetch stats on private npm packages by setting up a NODE_SECURE_TOKEN env variable (which must contain a npm token).

API

Use nsecure as API package to fetch and work with the JSON. The following example demonstrate how to retrieve the JSON Payload for mocha, cacache and is-wsl packages. It's possible to use the cwd method if you want to achieve similar work on local projects.

const { from } = require("nsecure");
const { writeFile } = require("fs").promises;

async function main() {
    const toFetch = ["mocha", "cacache", "is-wsl"];
    const options = { verbose: false };

    const payloads = await Promise.all(
        toFetch.map((name) => from(name, options))
    );

    const toWritePromise = [];
    for (let i = 0; i < toFetch.length; i++) {
        const fileName = `${toFetch[i]}.json`;
        const data = JSON.stringify(payloads[i], null, 2);

        toWritePromise.push(writeFile(fileName, data));
    }
    await Promise.all(toWritePromise);
}
main().catch(console.error);

Emojis and flags legends

emoji flag name description
☁️ isGit The package (project) is a git repository
🌲 hasIndirectDependencies The package have indirect dependencies.
⚠️ hasSuspectImport The package have suspect import.
⛔️ isDeprecated The package has been tagged as deprecated
📜 hasLicense The license is missing (or has not been detected)
📚 hasMultipleLicenses The package has multiple licenses in multiple files.
🔬 hasMinifiedCode The package has minified/uglified code
💎 hasCustomResolver The package has at least one dependency that is not a npm package (like a git link or a local file link)
🌍 hasExternalCapacity The package use at least one Node.js dependency capable to communicate outside or to establish a listening server
📦 hasScript has post and/or pre (un)install npm script
💕 hasManyPublishers The package has more than one publishers
👥 hasChangedAuthor The package "author" field has been updated at least one time
🚨 vulnerabilities The package have one or many vulnerabilities

Note: hasManyPublishers and hasChangedAuthor are not flags linked to a given package version (but to the package itself).

Fetching vulnerabilities

Right now, vulnerabilities are not shipped automatically because it request a manual action to hydrate a local .json file with all detected vulnerabilities from the Security WG repository.

To run the hydratation just run the following command in your terminal:

$ nsecure hydrate-db

License

MIT

About

Node.js security CLI / API that allow you to deeply analyze the dependency tree of a given package / directory

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages