| name | dependency-audit |
| description | Dependency audit: known CVEs, licence compliance, abandoned/outdated packages, lockfile integrity, and a
justification for every new dependency.
Trigger phrases: "dependency", "dependency audit", "npm audit", "package security", "CVE", "license"
|
Dependency Audit
Audit axes
- Known vulnerabilities (CVE): audit appropriate to the ecosystem
npm audit --production
dotnet list package --vulnerable
pip-audit
- License compliance: flag licenses incompatible with the project such as copyleft/GPL (a risk in commercial closed source).
- Maintenance status: note abandoned / long-unmaintained / single-maintainer packages.
- Transitive dependencies: also scan vulnerabilities in indirect dependencies.
- Lockfile integrity: lockfile committed and consistent with the manifest; versions pinned.
- Justification for new dependencies: is it actually needed? Don't add a heavy package for a single small function (supply-chain surface).
Output
Severity-sorted list: package · version · issue (CVE/license/maintenance) · upgrade path.
DoD
- 0 known HIGH/CRITICAL vulnerabilities; licenses compliant; lockfile consistent; every new package justified.