NPMScan
Was dieses MCP kann
Scans npm packages and dependency trees for vulnerabilities, malicious install behavior, license issues, maintainer risks, provenance concerns, and remediation priorities.
Tools
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['name'], 'properties': {'name': {'type': 'string', 'maxLength': 214, 'minLength': 1, 'description': 'Exact npm package name, e.g. "lodash" or "@scope/name"'}, 'version': {'type': 'string', 'maxLength': 128, 'minLength': 1, 'description': 'Exact version to analyze; omit to use the latest published version'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['name', 'version', 'npmscanUrl', 'hasLifecycleScripts', 'lifecycleScripts', 'filesScanned', 'scanNote', 'possibleTyposquatOf', 'findings', 'totalScore', 'riskTier'], 'properties': {'name': {'type': 'string'}, 'version': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'required': ['rule', 'text', 'points', 'note', 'locations'], 'properties': {'note': {'type': 'string'}, 'rule': {'type': 'string'}, 'text': {'type': 'string'}, 'points': {'type': 'number'}, 'locations': {'type': 'array', 'items': {'type': 'object', 'required': ['file', 'snippet'], 'properties': {'file': {'type': 'string'}, 'snippet': {'type': 'string'}}, 'additionalProperties': False}}}, 'additionalProperties': False}}, 'riskTier': {'enum': ['none', 'low', 'moderate', 'high', 'critical'], 'type': 'string'}, 'scanNote': {'type': ['string', 'null']}, 'npmscanUrl': {'type': 'string'}, 'totalScore': {'type': 'number'}, 'filesScanned': {'type': 'array', 'items': {'type': 'string'}}, 'lifecycleScripts': {'type': 'object', 'additionalProperties': {'type': 'string'}}, 'hasLifecycleScripts': {'type': 'boolean'}, 'possibleTyposquatOf': {'anyOf': [{'type': 'object', 'required': ['name', 'rank'], 'properties': {'name': {'type': 'string'}, 'rank': {'type': 'number'}}, 'additionalProperties': False}, {'type': 'null'}]}}, 'additionalProperties': False}
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['packages'], 'properties': {'maxDepth': {'type': 'integer', 'maximum': 3, 'minimum': 0, 'description': 'How many levels of transitive dependencies to expand beyond the given root packages (0 = only check the roots themselves). Default 2, capped at 3 to bound registry calls and stay within the request timeout.'}, 'packages': {'type': 'array', 'items': {'type': 'object', 'required': ['name'], 'properties': {'name': {'type': 'string', 'maxLength': 214, 'minLength': 1}, 'version': {'type': 'string', 'maxLength': 128}}, 'additionalProperties': False}, 'maxItems': 15, 'minItems': 1, 'description': '1-15 direct/root packages to expand from, e.g. a package.json\'s "dependencies". version accepts an exact version or a semver range like "^4.17.21"; omitted = latest.'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['summary', 'roots', 'maxDepth', 'nodes', 'vulnerablePaths', 'totalPackagesScanned', 'unresolvedCount', 'vulnerablePackageCount', 'totalVulnerabilities', 'truncated', 'truncationNote', 'enrichmentNote'], 'properties': {'nodes': {'type': 'array', 'items': {'type': 'object', 'required': ['name', 'actualName', 'version', 'depth', 'isRoot', 'rootPackages', 'parents', 'npmscanUrl', 'resolutionError', 'isVulnerable', 'highestSeverity', 'vulnerabilities'], 'properties': {'name': {'type': 'string'}, 'depth': {'type': 'number'}, 'isRoot': {'type': 'boolean'}, 'parents': {'type': 'array', 'items': {'type': 'string'}}, 'version': {'type': ['string', 'null']}, 'actualName': {'type': ['string', 'null']}, 'npmscanUrl': {'type': 'string'}, 'isVulnerable': {'type': ['boolean', 'null']}, 'rootPackages': {'type': 'array', 'items': {'type': 'string'}}, 'highestSeverity': {'type': ['string', 'null']}, 'resolutionError': {'type': ['string', 'null']}, 'vulnerabilities': {'type': 'array', 'items': {'type': 'object', 'required': ['id', 'summary', 'severity', 'aliases', 'publishedAt', 'fixedVersion', 'npmscanUrl'], 'properties': {'id': {'type': 'string'}, 'aliases': {'type': 'array', 'items': {'type': 'string'}}, 'summary': {'type': ['string', 'null']}, 'severity': {'type': ['string', 'null']}, 'npmscanUrl': {'type': 'string'}, 'publishedAt': {'type': ['string', 'null']}, 'fixedVersion': {'type': ['string', 'null']}}, 'additionalProperties': False}}}, 'additionalProperties': False}}, 'roots': {'type': 'array', 'items': {'type': 'object', 'required': ['name', 'requestedVersion'], 'properties': {'name': {'type': 'string'}, 'requestedVersion': {'type': ['string', 'null']}}, 'additionalProperties': False}}, 'summary': {'type': 'string'}, 'maxDepth': {'type': 'number'}, 'truncated': {'type': 'boolean'}, 'enrichmentNote': {'type': ['string', 'null']}, 'truncationNote': {'type': ['string', 'null']}, 'unresolvedCount': {'type': 'number'}, 'vulnerablePaths': {'type': 'array', 'items': {'type': 'object', 'required': ['name', 'version', 'highestSeverity', 'vulnerabilityCount', 'pulledInBy', 'npmscanUrl'], 'properties': {'name': {'type': 'string'}, 'version': {'type': 'string'}, 'npmscanUrl': {'type': 'string'}, 'pulledInBy': {'type': 'array', 'items': {'type': 'string'}}, 'highestSeverity': {'type': ['string', 'null']}, 'vulnerabilityCount': {'type': 'number'}}, 'additionalProperties': False}}, 'totalPackagesScanned': {'type': 'number'}, 'totalVulnerabilities': {'type': 'number'}, 'vulnerablePackageCount': {'type': 'number'}}, 'additionalProperties': False}
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['url'], 'properties': {'ref': {'type': 'string', 'maxLength': 250, 'minLength': 1, 'description': "Branch, tag, or commit SHA to audit. Omit to use the repository's default branch."}, 'url': {'type': 'string', 'maxLength': 500, 'minLength': 1, 'description': 'GitHub repository URL, e.g. "https://github.com/owner/repo".'}, 'policy': {'type': 'object', 'properties': {'deny': {'type': 'array', 'items': {'type': 'string', 'maxLength': 100, 'minLength': 1}, 'maxItems': 50, 'description': 'SPDX ids, family prefixes, or category names. Always takes precedence over allow.'}, 'allow': {'type': 'array', 'items': {'type': 'string', 'maxLength': 100, 'minLength': 1}, 'maxItems': 50, 'description': 'SPDX ids, family prefixes (e.g. "GPL"), or category names. Anything not matching is a violation.'}}, 'description': 'License allow/deny policy, same shape as check_license_compliance. Omit for the default policy (only copyleft/network-copyleft/proprietary are violations).', 'additionalProperties': False}, 'includeDevDependencies': {'type': 'boolean', 'description': 'Include package.json devDependencies in the audit. Default false. Ignored when a lockfile is used instead (its own format decides direct-dependency scope), and yarn.lock can never distinguish dev from production dependencies regardless of this flag.'}, 'includePeerDependencies': {'type': 'boolean', 'description': 'Include package.json peerDependencies (root and, for a monorepo, each workspace member) in the audit. Default false â\x80\x94 a peer is often intentionally left unresolved by the consumer. See warnings for which peers were excluded.'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['summary', 'owner', 'repoName', 'ref', 'defaultBranchUsed', 'manifestPath', 'lockfilePath', 'inputFormat', 'isMonorepo', 'workspacePatterns', 'workspacePackageCount', 'workspaceNote', 'policy', 'findings', 'overflowPackages', 'totalPackages', 'vulnerablePackageCount', 'licenseViolationCount', 'installScriptFlaggedCount', 'deepScannedCount', 'ownershipCheckedCount', 'ownershipRiskFlaggedCount', 'warnings', 'truncationNote', 'deepScanNote', 'ownershipCheckNote'], 'properties': {'ref': {'type': 'string'}, 'owner': {'type': 'string'}, 'policy': {'type': 'object', 'required': ['mode', 'allow', 'deny'], 'properties': {'deny': {'type': 'array', 'items': {'type': 'string'}}, 'mode': {'enum': ['default', 'allow', 'deny', 'allow+deny'], 'type': 'string'}, 'allow': {'type': 'array', 'items': {'type': 'string'}}}, 'additionalProperties': False}, 'summary': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'required': ['name', 'requestedVersion', 'resolvedVersion', 'npmscanUrl', 'deprecated', 'possibleTyposquatOf', 'isVulnerable', 'highestSeverity', 'vulnerabilities', 'rawLicense', 'licenseCategory', 'isLicenseCompliant', 'licenseNeedsReview', 'licenseViolation', 'hasLifecycleScripts', 'installScriptRiskTier', 'installScriptScore', 'installScriptScanScope', 'installScriptFindings', 'resolutionError', 'ownershipRiskEligible', 'ownershipRiskReason', 'ownershipRiskChecked', 'maintainerRiskTier', 'maintainerFindings', 'provenanceRiskTier', 'provenanceFindings'], 'properties': {'name': {'type': 'string'}, 'deprecated': {'type': ['string', 'null']}, 'npmscanUrl': {'type': 'string'}, 'rawLicense': {'type': ['string', 'null']}, 'isVulnerable': {'type': ['boolean', 'null']}, 'highestSeverity': {'type': ['string', 'null']}, 'licenseCategory': {'enum': ['permissive', 'weak-copyleft', 'copyleft', 'network-copyleft', 'proprietary', 'public-domain', 'unknown', 'mixed'], 'type': 'string'}, 'resolutionError': {'type': ['string', 'null']}, 'resolvedVersion': {'type': ['string', 'null']}, 'vulnerabilities': {'type': 'array', 'items': {'type': 'object', 'required': ['id', 'summary', 'severity', 'aliases', 'publishedAt', 'fixedVersion', 'npmscanUrl'], 'properties': {'id': {'type': 'string'}, 'aliases': {'type': 'array', 'items': {'type': 'string'}}, 'summary': {'type': ['string', 'null']}, 'severity': {'type': ['string', 'null']}, 'npmscanUrl': {'type': 'string'}, 'publishedAt': {'type': ['string', 'null']}, 'fixedVersion': {'type': ['string', 'null']}}, 'additionalProperties': False}}, 'licenseViolation': {'anyOf': [{'type': 'object', 'required': ['rule', 'text', 'note'], 'properties': {'note': {'type': 'string'}, 'rule': {'type': 'string'}, 'text': {'type': 'string'}}, 'additionalProperties': False}, {'type': 'null'}]}, 'requestedVersion': {'type': ['string', 'null']}, 'installScriptScore': {'type': ['number', 'null']}, 'isLicenseCompliant': {'type': ['boolean', 'null']}, 'licenseNeedsReview': {'type': 'boolean'}, 'maintainerFindings': {'anyOf': [{'type': 'array', 'items': {'$ref': '#/properties/findings/items/properties/installScriptFindings/anyOf/0/items'}}, {'type': 'null'}]}, 'maintainerRiskTier': {'anyOf': [{'$ref': '#/properties/findings/items/properties/installScriptRiskTier/anyOf/0'}, {'type': 'null'}]}, 'provenanceFindings': {'anyOf': [{'type': 'array', 'items': {'$ref': '#/properties/findings/items/properties/installScriptFindings/anyOf/0/items'}}, {'type': 'null'}]}, 'provenanceRiskTier': {'anyOf': [{'$ref': '#/properties/findings/items/properties/installScriptRiskTier/anyOf/0'}, {'type': 'null'}]}, 'hasLifecycleScripts': {'type': 'boolean'}, 'ownershipRiskReason': {'anyOf': [{'enum': ['critical-or-high-severity-vulnerability', 'possible-typosquat', 'deprecated'], 'type': 'string'}, {'type': 'null'}]}, 'possibleTyposquatOf': {'anyOf': [{'type': 'object', 'required': ['name', 'rank'], 'properties': {'name': {'type': 'string'}, 'rank': {'type': 'number'}}, 'additionalProperties': False}, {'type': 'null'}]}, 'ownershipRiskChecked': {'type': 'boolean'}, 'installScriptFindings': {'anyOf': [{'type': 'array', 'items': {'type': 'object', 'required': ['rule', 'text', 'points', 'note', 'locations'], 'properties': {'note': {'type': 'string'}, 'rule': {'type': 'string'}, 'text': {'type': 'string'}, 'points': {'type': 'number'}, 'locations': {'type': 'array', 'items': {'type': 'object', 'required': ['file', 'snippet'], 'properties': {'file': {'type': 'string'}, 'snippet': {'type': 'string'}}, 'additionalProperties': False}}}, 'additionalProperties': False}}, {'type': 'null'}]}, 'installScriptRiskTier': {'anyOf': [{'enum': ['none', 'low', 'moderate', 'high', 'critical'], 'type': 'string'}, {'type': 'null'}]}, 'ownershipRiskEligible': {'type': 'boolean'}, 'installScriptScanScope': {'anyOf': [{'enum': ['lifecycle-scripts-only', 'deep-tarball-scan'], 'type': 'string'}, {'type': 'null'}]}}, 'additionalProperties': False}}, 'repoName': {'type': 'string'}, 'warnings': {'type': 'array', 'items': {'type': 'string'}}, 'isMonorepo': {'type': 'boolean'}, 'inputFormat': {'enum': ['package.json', 'npm-lock', 'yarn-lock', 'pnpm-lock'], 'type': 'string'}, 'deepScanNote': {'type': ['string', 'null']}, 'lockfilePath': {'type': ['string', 'null']}, 'manifestPath': {'type': 'string'}, 'totalPackages': {'type': 'number'}, 'workspaceNote': {'type': ['string', 'null']}, 'truncationNote': {'type': ['string', 'null']}, 'deepScannedCount': {'type': 'number'}, 'overflowPackages': {'type': 'array', 'items': {'type': 'object', 'required': ['name', 'requestedVersion'], 'properties': {'name': {'type': 'string'}, 'requestedVersion': {'type': ['string', 'null']}}, 'additionalProperties': False}}, 'defaultBranchUsed': {'type': 'boolean'}, 'workspacePatterns': {'type': 'array', 'items': {'type': 'string'}}, 'ownershipCheckNote': {'type': ['string', 'null']}, 'licenseViolationCount': {'type': 'number'}, 'ownershipCheckedCount': {'type': 'number'}, 'workspacePackageCount': {'type': 'number'}, 'vulnerablePackageCount': {'type': 'number'}, 'installScriptFlaggedCount': {'type': 'number'}, 'ownershipRiskFlaggedCount': {'type': 'number'}}, 'additionalProperties': False}
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'content': {'type': 'string', 'minLength': 1, 'description': 'Raw dependency inventory content: package.json, package-lock.json, yarn.lock, pnpm-lock.yaml, CycloneDX JSON, or SPDX JSON. Use this OR `packages`, not both.'}, 'packages': {'type': 'array', 'items': {'type': 'object', 'required': ['name'], 'properties': {'name': {'type': 'string', 'maxLength': 214, 'minLength': 1}, 'version': {'type': 'string', 'maxLength': 128, 'description': 'One exact published version, e.g. "18.2.0" (not a range/tag like "^18.2.0" or "latest" â\x80\x94 those are resolved against the registry first, at the cost of an extra lookup, rather than rejected)'}}, 'additionalProperties': False}, 'maxItems': 1000, 'minItems': 1, 'description': 'Explicit package list (1-1000 items). Use this OR `content`, not both.'}, 'includeDevDependencies': {'type': 'boolean', 'description': 'Ignored when using `packages`; only applies when `content` is a manifest/lockfile format that distinguishes dev dependencies.'}, 'includePeerDependencies': {'type': 'boolean', 'description': 'Ignored when using `packages`; only applies when `content` is a package.json. peerDependencies are excluded from scanning by default (see ignoredPeerDependencyNames) since a peer is often intentionally left unresolved by the consumer â\x80\x94 set this to also check them.'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['results', 'totalVulnerabilities', 'totalUniqueVulnerabilities', 'packagesWithVulnerabilities'], 'properties': {'results': {'type': 'array', 'items': {'type': 'object', 'required': ['package', 'npmscanUrl', 'scanStatus', 'vulnerabilityCount', 'advisoryCount', 'uniqueVulnerabilityCount', 'vulnerabilities', 'signals', 'source'], 'properties': {'source': {'anyOf': [{'type': 'object', 'required': ['resolvedUrl', 'integrity', 'nonRegistryHost', 'identityMismatch', 'resolvedName', 'resolvedVersion'], 'properties': {'integrity': {'type': ['string', 'null']}, 'resolvedUrl': {'type': ['string', 'null']}, 'resolvedName': {'type': ['string', 'null']}, 'nonRegistryHost': {'type': ['boolean', 'null']}, 'resolvedVersion': {'type': ['string', 'null']}, 'identityMismatch': {'type': ['boolean', 'null']}}, 'additionalProperties': False}, {'type': 'null'}]}, 'package': {'type': 'object', 'required': ['name'], 'properties': {'name': {'type': 'string'}, 'version': {'type': 'string'}, 'actualName': {'type': 'string'}, 'declaredSpec': {'type': 'string'}}, 'additionalProperties': False}, 'signals': {'anyOf': [{'type': 'object', 'required': ['deprecated', 'hasInstallScripts', 'popularityTier', 'maintenanceTier', 'possibleTyposquatOf'], 'properties': {'deprecated': {'type': ['string', 'null']}, 'popularityTier': {'enum': ['very-high', 'high', 'moderate', 'low', 'very-low', 'unknown'], 'type': 'string'}, 'maintenanceTier': {'enum': ['active', 'aging', 'stale', 'unknown'], 'type': 'string'}, 'hasInstallScripts': {'type': ['boolean', 'null']}, 'possibleTyposquatOf': {'anyOf': [{'type': 'object', 'required': ['name', 'rank'], 'properties': {'name': {'type': 'string'}, 'rank': {'type': 'number'}}, 'additionalProperties': False}, {'type': 'null'}]}}, 'additionalProperties': False}, {'type': 'null'}]}, 'npmscanUrl': {'type': 'string'}, 'scanStatus': {'enum': ['scanned', 'not-scanned'], 'type': 'string'}, 'advisoryCount': {'type': 'number'}, 'vulnerabilities': {'type': 'array', 'items': {'type': 'object', 'required': ['id', 'summary', 'severity', 'aliases', 'publishedAt', 'fixedVersion', 'npmscanUrl'], 'properties': {'id': {'type': 'string'}, 'aliases': {'type': 'array', 'items': {'type': 'string'}}, 'summary': {'type': ['string', 'null']}, 'severity': {'type': ['string', 'null']}, 'npmscanUrl': {'type': 'string'}, 'publishedAt': {'type': ['string', 'null']}, 'fixedVersion': {'type': ['string', 'null']}}, 'additionalProperties': False}}, 'vulnerabilityCount': {'type': 'number'}, 'uniqueVulnerabilityCount': {'type': 'number'}}, 'additionalProperties': False}}, 'warnings': {'type': 'array', 'items': {'type': 'string'}}, 'inputFormat': {'type': 'string'}, 'ignoredCount': {'type': 'number'}, 'enrichmentNote': {'type': 'string'}, 'queryFailureCount': {'type': 'number'}, 'existenceCheckNote': {'type': 'string'}, 'parsedPackageCount': {'type': 'number'}, 'unresolvedPackages': {'type': 'array', 'items': {'type': 'string'}}, 'nonexistentVersions': {'type': 'array', 'items': {'type': 'string'}}, 'totalVulnerabilities': {'type': 'number'}, 'projectLifecycleScripts': {'anyOf': [{'type': 'object', 'additionalProperties': {'type': 'string'}}, {'type': 'null'}]}, 'ignoredPeerDependencyNames': {'type': 'array', 'items': {'type': 'string'}}, 'projectLifecycleScriptRisk': {'type': 'object', 'required': ['hasLifecycleScripts', 'riskTier', 'totalScore'], 'properties': {'riskTier': {'enum': ['none', 'low', 'moderate', 'high', 'critical'], 'type': 'string'}, 'totalScore': {'type': 'number'}, 'hasLifecycleScripts': {'type': 'boolean'}}, 'additionalProperties': False}, 'totalUniqueVulnerabilities': {'type': 'number'}, 'packagesWithVulnerabilities': {'type': 'number'}}, 'additionalProperties': False}
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['packages'], 'properties': {'policy': {'type': 'object', 'properties': {'deny': {'type': 'array', 'items': {'type': 'string', 'maxLength': 100, 'minLength': 1}, 'maxItems': 50, 'description': 'SPDX ids, family prefixes, or category names. Always takes precedence over allow.'}, 'allow': {'type': 'array', 'items': {'type': 'string', 'maxLength': 100, 'minLength': 1}, 'maxItems': 50, 'description': 'SPDX ids, family prefixes (e.g. "GPL"), or category names. Anything not matching is a violation.'}}, 'description': 'Omit entirely to use the default policy: only copyleft/network-copyleft/proprietary are violations.', 'additionalProperties': False}, 'packages': {'type': 'array', 'items': {'type': 'object', 'required': ['name'], 'properties': {'name': {'type': 'string', 'maxLength': 214, 'minLength': 1}, 'version': {'type': 'string', 'maxLength': 128}}, 'additionalProperties': False}, 'maxItems': 100, 'minItems': 1, 'description': '1-100 packages to check. version accepts an exact version or a semver range like "^4.17.21"; omitted = latest.'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['policy', 'summary', 'results', 'totalPackages', 'compliantCount', 'violationCount', 'needsReviewCount', 'unresolvedCount'], 'properties': {'policy': {'type': 'object', 'required': ['mode', 'allow', 'deny'], 'properties': {'deny': {'type': 'array', 'items': {'type': 'string'}}, 'mode': {'enum': ['default', 'allow', 'deny', 'allow+deny'], 'type': 'string'}, 'allow': {'type': 'array', 'items': {'type': 'string'}}}, 'additionalProperties': False}, 'results': {'type': 'array', 'items': {'type': 'object', 'required': ['package', 'npmscanUrl', 'resolvedVersion', 'rawLicense', 'category', 'isCompliant', 'needsReview', 'violation', 'resolutionError'], 'properties': {'package': {'type': 'object', 'required': ['name'], 'properties': {'name': {'type': 'string'}, 'version': {'type': 'string'}}, 'additionalProperties': False}, 'category': {'enum': ['permissive', 'weak-copyleft', 'copyleft', 'network-copyleft', 'proprietary', 'public-domain', 'unknown', 'mixed'], 'type': 'string'}, 'violation': {'anyOf': [{'type': 'object', 'required': ['rule', 'text', 'note'], 'properties': {'note': {'type': 'string'}, 'rule': {'type': 'string'}, 'text': {'type': 'string'}}, 'additionalProperties': False}, {'type': 'null'}]}, 'npmscanUrl': {'type': 'string'}, 'rawLicense': {'type': ['string', 'null']}, 'isCompliant': {'type': 'boolean'}, 'needsReview': {'type': 'boolean'}, 'resolutionError': {'type': ['string', 'null']}, 'resolvedVersion': {'type': ['string', 'null']}}, 'additionalProperties': False}}, 'summary': {'type': 'string'}, 'totalPackages': {'type': 'number'}, 'compliantCount': {'type': 'number'}, 'violationCount': {'type': 'number'}, 'unresolvedCount': {'type': 'number'}, 'needsReviewCount': {'type': 'number'}}, 'additionalProperties': False}
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['maintainerUsername'], 'properties': {'maintainerUsername': {'type': 'string', 'maxLength': 100, 'minLength': 1, 'description': 'Exact npm username, e.g. "sindresorhus" â\x80\x94 as shown at npmjs.com/~username. Not an email address, not a package name or scope.'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['maintainerUsername', 'npmscanUrl', 'npmProfileUrl', 'avatarUrl', 'totalPackagesFound', 'packagesReturned', 'resultsTruncated', 'clusterWindowHours', 'packages', 'clusters', 'findings', 'totalScore', 'riskTier', 'note'], 'properties': {'note': {'type': ['string', 'null']}, 'clusters': {'type': 'array', 'items': {'type': 'object', 'required': ['windowStart', 'windowEnd', 'packageNames', 'packageCount', 'combinedWeeklyDownloads', 'combinedDependentsCount', 'stillCurrentMaintainerCount'], 'properties': {'windowEnd': {'type': 'string'}, 'windowStart': {'type': 'string'}, 'packageCount': {'type': 'number'}, 'packageNames': {'type': 'array', 'items': {'type': 'string'}}, 'combinedDependentsCount': {'type': 'number'}, 'combinedWeeklyDownloads': {'type': 'number'}, 'stillCurrentMaintainerCount': {'type': 'number'}}, 'additionalProperties': False}}, 'findings': {'type': 'array', 'items': {'type': 'object', 'required': ['rule', 'text', 'points', 'note', 'locations'], 'properties': {'note': {'type': 'string'}, 'rule': {'type': 'string'}, 'text': {'type': 'string'}, 'points': {'type': 'number'}, 'locations': {'type': 'array', 'items': {'type': 'object', 'required': ['file', 'snippet'], 'properties': {'file': {'type': 'string'}, 'snippet': {'type': 'string'}}, 'additionalProperties': False}}}, 'additionalProperties': False}}, 'packages': {'type': 'array', 'items': {'type': 'object', 'required': ['name', 'version', 'lastPublished', 'weeklyDownloads', 'dependentsCount', 'isCurrentMaintainer', 'npmscanUrl'], 'properties': {'name': {'type': 'string'}, 'version': {'type': 'string'}, 'npmscanUrl': {'type': 'string'}, 'lastPublished': {'type': ['string', 'null']}, 'dependentsCount': {'type': ['number', 'null']}, 'weeklyDownloads': {'type': ['number', 'null']}, 'isCurrentMaintainer': {'type': 'boolean'}}, 'additionalProperties': False}}, 'riskTier': {'enum': ['none', 'low', 'moderate', 'high', 'critical'], 'type': 'string'}, 'avatarUrl': {'type': ['string', 'null']}, 'npmscanUrl': {'type': 'string'}, 'totalScore': {'type': 'number'}, 'npmProfileUrl': {'type': 'string'}, 'packagesReturned': {'type': 'number'}, 'resultsTruncated': {'type': 'boolean'}, 'clusterWindowHours': {'type': 'number'}, 'maintainerUsername': {'type': 'string'}, 'totalPackagesFound': {'type': 'number'}}, 'additionalProperties': False}
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['name'], 'properties': {'name': {'type': 'string', 'maxLength': 214, 'minLength': 1, 'description': 'Exact npm package name, e.g. "lodash" or "@scope/name"'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['name', 'npmscanUrl', 'lookbackDays', 'currentMaintainers', 'history', 'repository', 'findings', 'totalScore', 'riskTier'], 'properties': {'name': {'type': 'string'}, 'history': {'type': 'object', 'required': ['versionsConsidered', 'firstTrackedVersion', 'latestTrackedVersion', 'latestVersionPublishedViaTrustedPublisher', 'changes', 'changesTruncated', 'note'], 'properties': {'note': {'type': ['string', 'null']}, 'changes': {'type': 'array', 'items': {'type': 'object', 'required': ['version', 'publishedAt', 'added', 'removed'], 'properties': {'added': {'type': 'array', 'items': {'type': 'string'}}, 'removed': {'type': 'array', 'items': {'type': 'string'}}, 'version': {'type': ['string', 'null']}, 'publishedAt': {'type': ['string', 'null']}}, 'additionalProperties': False}}, 'changesTruncated': {'type': 'boolean'}, 'versionsConsidered': {'type': 'number'}, 'firstTrackedVersion': {'anyOf': [{'type': 'object', 'required': ['version', 'publishedAt'], 'properties': {'version': {'type': 'string'}, 'publishedAt': {'type': 'string'}}, 'additionalProperties': False}, {'type': 'null'}]}, 'latestTrackedVersion': {'anyOf': [{'type': 'object', 'required': ['version', 'publishedAt'], 'properties': {'version': {'type': 'string'}, 'publishedAt': {'type': 'string'}}, 'additionalProperties': False}, {'type': 'null'}]}, 'latestVersionPublishedViaTrustedPublisher': {'type': 'boolean'}}, 'additionalProperties': False}, 'findings': {'type': 'array', 'items': {'type': 'object', 'required': ['rule', 'text', 'points', 'note', 'locations'], 'properties': {'note': {'type': 'string'}, 'rule': {'type': 'string'}, 'text': {'type': 'string'}, 'points': {'type': 'number'}, 'locations': {'type': 'array', 'items': {'type': 'object', 'required': ['file', 'snippet'], 'properties': {'file': {'type': 'string'}, 'snippet': {'type': 'string'}}, 'additionalProperties': False}}}, 'additionalProperties': False}}, 'riskTier': {'enum': ['none', 'low', 'moderate', 'high', 'critical'], 'type': 'string'}, 'npmscanUrl': {'type': 'string'}, 'repository': {'type': 'object', 'required': ['checked', 'declaredRepository', 'currentFullName', 'transferred', 'archived', 'reachable', 'ownerLogin', 'ownerAvatarUrl', 'note'], 'properties': {'note': {'type': ['string', 'null']}, 'checked': {'type': 'boolean'}, 'archived': {'type': ['boolean', 'null']}, 'reachable': {'type': ['boolean', 'null']}, 'ownerLogin': {'type': ['string', 'null']}, 'transferred': {'type': ['boolean', 'null']}, 'ownerAvatarUrl': {'type': ['string', 'null']}, 'currentFullName': {'type': ['string', 'null']}, 'declaredRepository': {'type': ['string', 'null']}}, 'additionalProperties': False}, 'totalScore': {'type': 'number'}, 'lookbackDays': {'type': 'number'}, 'currentMaintainers': {'type': 'array', 'items': {'type': 'object', 'required': ['name', 'email'], 'properties': {'name': {'type': 'string'}, 'email': {'type': ['string', 'null']}}, 'additionalProperties': False}}}, 'additionalProperties': False}
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['name'], 'properties': {'name': {'type': 'string', 'maxLength': 214, 'minLength': 1, 'description': 'Exact npm package name, e.g. "lodash" or "@scope/name"'}, 'version': {'type': 'string', 'maxLength': 128, 'minLength': 1, 'description': 'Exact version to check; omit to use the latest published version'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['name', 'version', 'npmscanUrl', 'provenance', 'peers', 'sourceDiff', 'findings', 'totalScore', 'riskTier'], 'properties': {'name': {'type': 'string'}, 'peers': {'type': 'object', 'required': ['orgKind', 'orgIdentifier', 'peersChecked', 'peersWithProvenance', 'peerProvenanceRate', 'note'], 'properties': {'note': {'type': ['string', 'null']}, 'orgKind': {'anyOf': [{'enum': ['scope', 'maintainer'], 'type': 'string'}, {'type': 'null'}]}, 'peersChecked': {'type': 'number'}, 'orgIdentifier': {'type': ['string', 'null']}, 'peerProvenanceRate': {'type': ['number', 'null']}, 'peersWithProvenance': {'type': 'number'}}, 'additionalProperties': False}, 'version': {'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'required': ['rule', 'text', 'points', 'note', 'locations'], 'properties': {'note': {'type': 'string'}, 'rule': {'type': 'string'}, 'text': {'type': 'string'}, 'points': {'type': 'number'}, 'locations': {'type': 'array', 'items': {'type': 'object', 'required': ['file', 'snippet'], 'properties': {'file': {'type': 'string'}, 'snippet': {'type': 'string'}}, 'additionalProperties': False}}}, 'additionalProperties': False}}, 'riskTier': {'enum': ['none', 'low', 'moderate', 'high', 'critical'], 'type': 'string'}, 'npmscanUrl': {'type': 'string'}, 'provenance': {'type': 'object', 'required': ['hasProvenance', 'predicateType', 'sourceRepository', 'workflowPath', 'builderId', 'sourceCommit', 'buildRunUrl', 'declaredRepository', 'repositoryMatchesBuild', 'note'], 'properties': {'note': {'type': ['string', 'null']}, 'builderId': {'type': ['string', 'null']}, 'buildRunUrl': {'type': ['string', 'null']}, 'sourceCommit': {'type': ['string', 'null']}, 'workflowPath': {'type': ['string', 'null']}, 'hasProvenance': {'type': 'boolean'}, 'predicateType': {'type': ['string', 'null']}, 'sourceRepository': {'type': ['string', 'null']}, 'declaredRepository': {'type': ['string', 'null']}, 'repositoryMatchesBuild': {'type': ['boolean', 'null']}}, 'additionalProperties': False}, 'sourceDiff': {'type': 'object', 'required': ['checked', 'gitRef', 'refSource', 'addedInstallScripts', 'addedDependencies', 'note'], 'properties': {'note': {'type': ['string', 'null']}, 'gitRef': {'type': ['string', 'null']}, 'checked': {'type': 'boolean'}, 'refSource': {'anyOf': [{'enum': ['provenance-commit', 'guessed-tag'], 'type': 'string'}, {'type': 'null'}]}, 'addedDependencies': {'type': 'array', 'items': {'type': 'string'}}, 'addedInstallScripts': {'type': 'array', 'items': {'type': 'string'}}}, 'additionalProperties': False}, 'totalScore': {'type': 'number'}}, 'additionalProperties': False}
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['packages'], 'properties': {'packages': {'type': 'array', 'items': {'type': 'string', 'maxLength': 214, 'minLength': 1}, 'maxItems': 5, 'minItems': 2, 'description': '2-5 exact npm package names to compare, e.g. ["axios", "got", "node-fetch"].'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['candidates', 'differentiators', 'recommendation'], 'properties': {'candidates': {'type': 'array', 'items': {'type': 'object', 'required': ['name', 'found', 'resolutionError', 'npmscanUrl', 'description', 'license', 'latestVersion', 'deprecated', 'weeklyDownloads', 'downloadTrend', 'githubStars', 'hasBuiltInTypes', 'daysSinceLastPublish', 'popularityTier', 'maintenanceTier', 'maintenanceSummary', 'possibleTyposquatOf', 'isLatestVersionVulnerable', 'vulnerabilityCheckFailed', 'highestSeverity', 'vulnerabilityCount', 'installScriptRisk', 'installSize', 'score'], 'properties': {'name': {'type': 'string'}, 'found': {'type': 'boolean'}, 'score': {'type': ['number', 'null']}, 'license': {'type': ['string', 'null']}, 'deprecated': {'type': ['string', 'null']}, 'npmscanUrl': {'type': 'string'}, 'description': {'type': ['string', 'null']}, 'githubStars': {'type': ['number', 'null']}, 'installSize': {'anyOf': [{'type': 'object', 'required': ['unpackedSize', 'transitive'], 'properties': {'transitive': {'type': 'object', 'required': ['transitiveUnpackedSize', 'transitiveDependencyCount', 'sizeUnknownCount', 'truncated'], 'properties': {'truncated': {'type': 'boolean'}, 'sizeUnknownCount': {'type': 'number'}, 'transitiveUnpackedSize': {'type': ['number', 'null']}, 'transitiveDependencyCount': {'type': 'number'}}, 'additionalProperties': False}, 'unpackedSize': {'type': ['number', 'null']}}, 'additionalProperties': False}, {'type': 'null'}]}, 'downloadTrend': {'type': 'object', 'required': ['direction', 'changePercent'], 'properties': {'direction': {'enum': ['growing', 'stable', 'declining', 'unknown'], 'type': 'string'}, 'changePercent': {'type': ['number', 'null']}}, 'additionalProperties': False}, 'latestVersion': {'type': ['string', 'null']}, 'popularityTier': {'enum': ['very-high', 'high', 'moderate', 'low', 'very-low', 'unknown'], 'type': 'string'}, 'hasBuiltInTypes': {'type': 'boolean'}, 'highestSeverity': {'type': ['string', 'null']}, 'maintenanceTier': {'enum': ['active', 'aging', 'stale', 'unknown'], 'type': 'string'}, 'resolutionError': {'type': ['string', 'null']}, 'weeklyDownloads': {'type': ['number', 'null']}, 'installScriptRisk': {'anyOf': [{'type': 'object', 'required': ['hasLifecycleScripts', 'riskTier', 'totalScore', 'scanScope'], 'properties': {'riskTier': {'enum': ['none', 'low', 'moderate', 'high', 'critical'], 'type': 'string'}, 'scanScope': {'type': 'string', 'const': 'lifecycle-scripts-only'}, 'totalScore': {'type': 'number'}, 'hasLifecycleScripts': {'type': 'boolean'}}, 'additionalProperties': False}, {'type': 'null'}]}, 'maintenanceSummary': {'type': 'string'}, 'vulnerabilityCount': {'type': 'number'}, 'possibleTyposquatOf': {'anyOf': [{'type': 'object', 'required': ['name', 'rank'], 'properties': {'name': {'type': 'string'}, 'rank': {'type': 'number'}}, 'additionalProperties': False}, {'type': 'null'}]}, 'daysSinceLastPublish': {'type': ['number', 'null']}, 'vulnerabilityCheckFailed': {'type': 'boolean'}, 'isLatestVersionVulnerable': {'type': 'boolean'}}, 'additionalProperties': False}}, 'recommendation': {'type': 'object', 'required': ['pick', 'runnerUp', 'rationale', 'confidence'], 'properties': {'pick': {'type': ['string', 'null']}, 'runnerUp': {'type': ['string', 'null']}, 'rationale': {'type': 'string'}, 'confidence': {'enum': ['high', 'medium', 'low'], 'type': 'string'}}, 'additionalProperties': False}, 'differentiators': {'type': 'object', 'required': ['mostDownloads', 'mostGithubStars', 'hasTypeScriptSupport', 'hasKnownVulnerabilities', 'deprecated', 'possibleTyposquat', 'installScriptRiskFlagged', 'smallestInstallSize', 'largestInstallSize'], 'properties': {'deprecated': {'type': 'array', 'items': {'type': 'string'}}, 'mostDownloads': {'type': ['string', 'null']}, 'mostGithubStars': {'type': ['string', 'null']}, 'possibleTyposquat': {'type': 'array', 'items': {'type': 'string'}}, 'largestInstallSize': {'type': ['string', 'null']}, 'smallestInstallSize': {'type': ['string', 'null']}, 'hasTypeScriptSupport': {'type': 'array', 'items': {'type': 'string'}}, 'hasKnownVulnerabilities': {'type': 'array', 'items': {'type': 'string'}}, 'installScriptRiskFlagged': {'type': 'array', 'items': {'type': 'string'}}}, 'additionalProperties': False}}, 'additionalProperties': False}
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['before', 'after'], 'properties': {'after': {'type': 'string', 'maxLength': 8388608, 'minLength': 1, 'description': 'Raw file content of the "after" snapshot â\x80\x94 a package.json, package-lock.json (npm v1-v3), yarn.lock (classic v1 or Berry), or pnpm-lock.yaml. Format is auto-detected; before/after may be different formats.'}, 'before': {'type': 'string', 'maxLength': 8388608, 'minLength': 1, 'description': 'Raw file content of the "before" snapshot â\x80\x94 a package.json, package-lock.json (npm v1-v3), yarn.lock (classic v1 or Berry), or pnpm-lock.yaml. Format is auto-detected; before/after may be different formats.'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['summary', 'beforeFormat', 'afterFormat', 'comparisonNote', 'added', 'removed', 'changed', 'totalAdded', 'totalRemoved', 'totalChanged', 'flaggedCount', 'truncated', 'truncationNote', 'enrichmentNote', 'projectLifecycleChanges', 'overridesChanges'], 'properties': {'added': {'type': 'array', 'items': {'type': 'object', 'required': ['name', 'actualName', 'npmscanUrl', 'beforeVersion', 'afterVersion', 'coexistingVersions', 'changeType', 'hasInstallScript', 'installScriptIntroduced', 'installScriptKeys', 'installScriptKeysIntroduced', 'sourceIntegrityChanged', 'resolvedUrl', 'integrity', 'isVulnerable', 'highestSeverity', 'vulnerabilities', 'vulnerabilityDelta', 'resolutionNote'], 'properties': {'name': {'type': 'string'}, 'integrity': {'type': ['string', 'null']}, 'actualName': {'type': ['string', 'null']}, 'changeType': {'anyOf': [{'enum': ['upgrade', 'downgrade', 'unresolved'], 'type': 'string'}, {'type': 'null'}]}, 'npmscanUrl': {'type': 'string'}, 'resolvedUrl': {'type': ['string', 'null']}, 'afterVersion': {'type': ['string', 'null']}, 'isVulnerable': {'type': ['boolean', 'null']}, 'beforeVersion': {'type': ['string', 'null']}, 'resolutionNote': {'type': ['string', 'null']}, 'highestSeverity': {'type': ['string', 'null']}, 'vulnerabilities': {'type': 'array', 'items': {'type': 'object', 'required': ['id', 'summary', 'severity', 'aliases', 'publishedAt', 'fixedVersion', 'npmscanUrl'], 'properties': {'id': {'type': 'string'}, 'aliases': {'type': 'array', 'items': {'type': 'string'}}, 'summary': {'type': ['string', 'null']}, 'severity': {'type': ['string', 'null']}, 'npmscanUrl': {'type': 'string'}, 'publishedAt': {'type': ['string', 'null']}, 'fixedVersion': {'type': ['string', 'null']}}, 'additionalProperties': False}}, 'hasInstallScript': {'type': ['boolean', 'null']}, 'installScriptKeys': {'anyOf': [{'type': 'array', 'items': {'enum': ['preinstall', 'install', 'postinstall', 'prepare'], 'type': 'string'}}, {'type': 'null'}]}, 'coexistingVersions': {'anyOf': [{'type': 'array', 'items': {'type': 'string'}}, {'type': 'null'}]}, 'vulnerabilityDelta': {'anyOf': [{'enum': ['introduced', 'fixed', 'still-vulnerable', 'still-clean', 'unknown'], 'type': 'string'}, {'type': 'null'}]}, 'sourceIntegrityChanged': {'type': ['boolean', 'null']}, 'installScriptIntroduced': {'type': ['boolean', 'null']}, 'installScriptKeysIntroduced': {'anyOf': [{'type': 'array', 'items': {'enum': ['preinstall', 'install', 'postinstall', 'prepare'], 'type': 'string'}}, {'type': 'null'}]}}, 'additionalProperties': False}}, 'changed': {'type': 'array', 'items': {'$ref': '#/properties/added/items'}}, 'removed': {'type': 'array', 'items': {'type': 'object', 'required': ['name', 'actualName', 'version', 'npmscanUrl'], 'properties': {'name': {'type': 'string'}, 'version': {'type': ['string', 'null']}, 'actualName': {'type': ['string', 'null']}, 'npmscanUrl': {'type': 'string'}}, 'additionalProperties': False}}, 'summary': {'type': 'string'}, 'truncated': {'type': 'boolean'}, 'totalAdded': {'type': 'number'}, 'afterFormat': {'enum': ['package.json', 'npm-lock', 'yarn-lock', 'pnpm-lock'], 'type': 'string'}, 'beforeFormat': {'enum': ['package.json', 'npm-lock', 'yarn-lock', 'pnpm-lock'], 'type': 'string'}, 'flaggedCount': {'type': 'number'}, 'totalChanged': {'type': 'number'}, 'totalRemoved': {'type': 'number'}, 'comparisonNote': {'type': ['string', 'null']}, 'enrichmentNote': {'type': ['string', 'null']}, 'truncationNote': {'type': ['string', 'null']}, 'overridesChanges': {'anyOf': [{'type': 'object', 'required': ['introduced', 'removed', 'changed'], 'properties': {'changed': {'type': 'object', 'additionalProperties': {'type': 'object', 'required': ['before', 'after'], 'properties': {'after': {'type': 'string'}, 'before': {'type': 'string'}}, 'additionalProperties': False}}, 'removed': {'type': 'object', 'additionalProperties': {'type': 'string'}}, 'introduced': {'type': 'object', 'additionalProperties': {'type': 'string'}}}, 'additionalProperties': False}, {'type': 'null'}]}, 'projectLifecycleChanges': {'anyOf': [{'type': 'object', 'required': ['introduced', 'removed', 'changed'], 'properties': {'changed': {'type': 'object', 'additionalProperties': {'type': 'object', 'required': ['before', 'after'], 'properties': {'after': {'type': 'string'}, 'before': {'type': 'string'}}, 'additionalProperties': False}}, 'removed': {'type': 'object', 'additionalProperties': {'type': 'string'}}, 'introduced': {'type': 'object', 'additionalProperties': {'type': 'string'}}}, 'additionalProperties': False}, {'type': 'null'}]}}, 'additionalProperties': False}
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['content'], 'properties': {'content': {'type': 'string', 'minLength': 1, 'description': 'Raw stdout of `npm audit --json` â\x80\x94 either npm 7+ format ({"auditReportVersion": 2, "vulnerabilities": {...}}) or legacy npm 6 format ({"advisories": {...}}).'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['inputFormat', 'totalFindings', 'uniqueCveCount', 'ghsaResolvedToCveCount', 'summary', 'ranked', 'warnings', 'skippedCount'], 'properties': {'ranked': {'type': 'array', 'items': {'type': 'object', 'required': ['rank', 'packageName', 'cveId', 'advisoryId', 'currentVersion', 'fixedVersion', 'severity', 'kev', 'epss', 'score', 'tier', 'findingType', 'reason', 'npmscanUrl', 'cveNpmscanUrl', 'advisoryTitle', 'isDirect', 'fixAvailable', 'fixTarget'], 'properties': {'kev': {'anyOf': [{'type': 'object', 'required': ['dateAdded', 'dueDate', 'knownRansomwareCampaignUse', 'requiredAction'], 'properties': {'dueDate': {'type': 'string'}, 'dateAdded': {'type': 'string'}, 'requiredAction': {'type': 'string'}, 'knownRansomwareCampaignUse': {'type': 'string'}}, 'additionalProperties': False}, {'type': 'null'}]}, 'epss': {'anyOf': [{'type': 'object', 'required': ['score', 'percentile', 'date'], 'properties': {'date': {'type': 'string'}, 'score': {'type': 'number'}, 'percentile': {'type': 'number'}}, 'additionalProperties': False}, {'type': 'null'}]}, 'rank': {'type': 'number'}, 'tier': {'enum': ['remove-now', 'patch-now', 'patch-soon', 'scheduled', 'monitor'], 'type': 'string'}, 'cveId': {'type': ['string', 'null']}, 'score': {'type': 'number'}, 'reason': {'type': 'string'}, 'isDirect': {'type': ['boolean', 'null']}, 'severity': {'type': ['string', 'null']}, 'fixTarget': {'anyOf': [{'type': 'object', 'required': ['name', 'version', 'isSemVerMajor'], 'properties': {'name': {'type': 'string'}, 'version': {'type': 'string'}, 'isSemVerMajor': {'type': 'boolean'}}, 'additionalProperties': False}, {'type': 'null'}]}, 'advisoryId': {'type': ['string', 'null']}, 'npmscanUrl': {'type': 'string'}, 'findingType': {'enum': ['malware', 'vulnerability', 'supply-chain', 'install-script'], 'type': 'string'}, 'packageName': {'type': 'string'}, 'fixAvailable': {'type': ['boolean', 'null']}, 'fixedVersion': {'type': ['string', 'null']}, 'advisoryTitle': {'type': ['string', 'null']}, 'cveNpmscanUrl': {'type': ['string', 'null']}, 'currentVersion': {'type': ['string', 'null']}}, 'additionalProperties': False}}, 'summary': {'type': 'object', 'required': ['removeNow', 'patchNow', 'patchSoon', 'scheduled', 'monitor', 'kevListedCount'], 'properties': {'monitor': {'type': 'number'}, 'patchNow': {'type': 'number'}, 'patchSoon': {'type': 'number'}, 'removeNow': {'type': 'number'}, 'scheduled': {'type': 'number'}, 'kevListedCount': {'type': 'number'}}, 'additionalProperties': False}, 'warnings': {'type': 'array', 'items': {'type': 'string'}}, 'inputFormat': {'enum': ['npm-audit-v2', 'npm-audit-legacy'], 'type': 'string'}, 'skippedCount': {'type': 'number'}, 'totalFindings': {'type': 'number'}, 'uniqueCveCount': {'type': 'number'}, 'ghsaResolvedToCveCount': {'type': 'number'}}, 'additionalProperties': False}
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'format': {'enum': ['cyclonedx', 'spdx'], 'type': 'string', 'description': "SBOM format to emit. Default 'cyclonedx'."}, 'policy': {'type': 'object', 'properties': {'deny': {'type': 'array', 'items': {'type': 'string', 'maxLength': 100, 'minLength': 1}, 'maxItems': 50, 'description': 'SPDX ids, family prefixes, or category names. Always takes precedence over allow.'}, 'allow': {'type': 'array', 'items': {'type': 'string', 'maxLength': 100, 'minLength': 1}, 'maxItems': 50, 'description': 'SPDX ids, family prefixes (e.g. "GPL"), or category names. Anything not matching is a violation.'}}, 'description': 'License allow/deny policy, same shape as check_license_compliance. Omit for the default policy.', 'additionalProperties': False}, 'content': {'type': 'string', 'minLength': 1, 'description': 'Raw dependency inventory content: package.json, package-lock.json, yarn.lock, pnpm-lock.yaml, CycloneDX JSON, or SPDX JSON. Use this OR `packages`, not both.'}, 'packages': {'type': 'array', 'items': {'type': 'object', 'required': ['name'], 'properties': {'name': {'type': 'string', 'maxLength': 214, 'minLength': 1}, 'version': {'type': 'string', 'maxLength': 128}}, 'additionalProperties': False}, 'maxItems': 1000, 'minItems': 1, 'description': 'Explicit package list (1-1000 items, capped to 100 when includeLicenses is on). Use this OR `content`, not both.'}, 'componentName': {'type': 'string', 'maxLength': 214, 'minLength': 1, 'description': "Name of the SBOM's own root component/document, if known."}, 'includeLicenses': {'type': 'boolean', 'description': 'Resolve registry license data and embed it natively. Default true.'}, 'componentVersion': {'type': 'string', 'maxLength': 128, 'minLength': 1}, 'includeDevDependencies': {'type': 'boolean', 'description': 'Ignored when using `packages`; only applies when `content` is a manifest/lockfile format that distinguishes dev dependencies.'}, 'includeVulnerabilities': {'type': 'boolean', 'description': 'Query OSV.dev and embed findings natively. Default true.'}, 'includePeerDependencies': {'type': 'boolean', 'description': 'Ignored when using `packages`; only applies when `content` is a package.json. peerDependencies are excluded by default â\x80\x94 set this to also include them as SBOM components.'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['format', 'sbom', 'parsedPackageCount', 'totalVulnerabilities', 'packagesWithVulnerabilities'], 'properties': {'sbom': {'type': 'object', 'additionalProperties': {}}, 'format': {'enum': ['cyclonedx', 'spdx'], 'type': 'string'}, 'policy': {'type': 'object', 'required': ['mode', 'allow', 'deny'], 'properties': {'deny': {'type': 'array', 'items': {'type': 'string'}}, 'mode': {'enum': ['default', 'allow', 'deny', 'allow+deny'], 'type': 'string'}, 'allow': {'type': 'array', 'items': {'type': 'string'}}}, 'additionalProperties': False}, 'warnings': {'type': 'array', 'items': {'type': 'string'}}, 'inputFormat': {'type': 'string'}, 'ignoredCount': {'type': 'number'}, 'enrichmentNote': {'type': 'string'}, 'parsedPackageCount': {'type': 'number'}, 'totalVulnerabilities': {'type': 'number'}, 'licenseViolationCount': {'type': 'number'}, 'packagesWithVulnerabilities': {'type': 'number'}}, 'additionalProperties': False}
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'cveId': {'type': 'string', 'pattern': '^CVE-\\d{4}-\\d{4,}$', 'description': 'Exact CVE ID for a single lookup, e.g. "CVE-2026-2950". When given, search filters below are ignored and should be omitted.'}, 'cweId': {'type': 'string', 'pattern': '^CWE-\\d+$', 'description': 'Filter by weakness type, e.g. "CWE-79"'}, 'severity': {'enum': ['CRITICAL', 'HIGH', 'MEDIUM', 'LOW'], 'type': 'string', 'description': 'Filter by CVSS v3 base severity'}, 'startIndex': {'type': 'integer', 'minimum': 0, 'description': 'Pagination offset for a search'}, 'keywordSearch': {'type': 'string', 'maxLength': 200, 'minLength': 1, 'description': 'Free-text search, e.g. a package or product name'}, 'publishedSince': {'type': 'string', 'pattern': '^\\d{4}-\\d{2}-\\d{2}$', 'description': 'Publication date range start (YYYY-MM-DD). Must be given together with publishedUntil.'}, 'publishedUntil': {'$ref': '#/properties/publishedSince', 'description': 'Publication date range end (YYYY-MM-DD). Must be given together with publishedSince; range is capped at 120 days.'}, 'resultsPerPage': {'type': 'integer', 'maximum': 50, 'minimum': 1, 'description': 'Max results for a search (default 10, capped at 50)'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'id': {'type': 'string'}, 'kev': {'anyOf': [{'type': 'object', 'required': ['dateAdded', 'dueDate', 'knownRansomwareCampaignUse', 'requiredAction'], 'properties': {'dueDate': {'type': 'string'}, 'dateAdded': {'type': 'string'}, 'requiredAction': {'type': 'string'}, 'knownRansomwareCampaignUse': {'type': 'string'}}, 'additionalProperties': False}, {'type': 'null'}]}, 'cves': {'type': 'array', 'items': {'type': 'object', 'required': ['id', 'npmscanUrl', 'vulnStatus', 'description', 'published', 'lastModified', 'cvss', 'cwes', 'references', 'source', 'kev', 'epss', 'kevCheckFailed', 'epssCheckFailed'], 'properties': {'id': {'$ref': '#/properties/id'}, 'kev': {'$ref': '#/properties/kev'}, 'cvss': {'$ref': '#/properties/cvss'}, 'cwes': {'$ref': '#/properties/cwes'}, 'epss': {'$ref': '#/properties/epss'}, 'source': {'$ref': '#/properties/source'}, 'published': {'$ref': '#/properties/published'}, 'npmscanUrl': {'$ref': '#/properties/npmscanUrl'}, 'references': {'$ref': '#/properties/references'}, 'vulnStatus': {'$ref': '#/properties/vulnStatus'}, 'description': {'$ref': '#/properties/description'}, 'lastModified': {'$ref': '#/properties/lastModified'}, 'kevCheckFailed': {'$ref': '#/properties/kevCheckFailed'}, 'epssCheckFailed': {'$ref': '#/properties/epssCheckFailed'}}, 'additionalProperties': False}}, 'cvss': {'anyOf': [{'type': 'object', 'required': ['version', 'baseScore', 'baseSeverity', 'vectorString'], 'properties': {'version': {'enum': ['3.1', '3.0', '2.0'], 'type': 'string'}, 'baseScore': {'type': 'number'}, 'baseSeverity': {'type': ['string', 'null']}, 'vectorString': {'type': 'string'}}, 'additionalProperties': False}, {'type': 'null'}]}, 'cwes': {'type': 'array', 'items': {'type': 'string'}}, 'epss': {'anyOf': [{'type': 'object', 'required': ['score', 'percentile', 'date'], 'properties': {'date': {'type': 'string'}, 'score': {'type': 'number'}, 'percentile': {'type': 'number'}}, 'additionalProperties': False}, {'type': 'null'}]}, 'note': {'type': 'string'}, 'cveId': {'type': 'string'}, 'found': {'type': 'boolean'}, 'source': {'enum': ['nvd', 'mitre'], 'type': 'string'}, 'published': {'type': ['string', 'null']}, 'npmscanUrl': {'type': 'string'}, 'references': {'type': 'array', 'items': {'type': 'object', 'required': ['url', 'source', 'tags'], 'properties': {'url': {'type': 'string'}, 'tags': {'type': 'array', 'items': {'type': 'string'}}, 'source': {'type': ['string', 'null']}}, 'additionalProperties': False}}, 'startIndex': {'type': 'number'}, 'vulnStatus': {'type': ['string', 'null']}, 'description': {'type': ['string', 'null']}, 'lastModified': {'type': ['string', 'null']}, 'totalResults': {'type': 'number'}, 'kevCheckFailed': {'type': 'boolean'}, 'resultsPerPage': {'type': 'number'}, 'epssCheckFailed': {'type': 'boolean'}, 'dateRangeClamped': {'type': 'boolean'}}, 'additionalProperties': False}
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'type': {'enum': ['reviewed', 'malware', 'osv'], 'type': 'string', 'description': 'Advisory source: "reviewed" (curated CVE-style, default), "malware" (GitHub-curated known-malicious packages), or "osv" (OSV.dev/OpenSSF malicious-packages feed)'}, 'cveId': {'type': 'string', 'description': 'Look up one exact advisory by its CVE ID (e.g. "CVE-2024-12345") â\x80\x94 reviewed/malware only'}, 'cursor': {'type': 'string', 'description': "Opaque pagination cursor from a previous response's nextCursor, to fetch the next page"}, 'ghsaId': {'type': 'string', 'description': 'Look up one exact advisory by its GHSA ID (e.g. "GHSA-xxxx-xxxx-xxxx") â\x80\x94 reviewed/malware only'}, 'affects': {'type': 'string', 'maxLength': 214, 'description': 'Filter to advisories affecting this npm package name'}, 'category': {'enum': ['access-control', 'dos', 'xss', 'ssrf', 'auth', 'code-injection', 'info-exposure', 'path-traversal', 'input-validation', 'prototype-pollution', 'command-injection', 'sqli', 'crypto', 'race-condition', 'open-redirect', 'csrf', 'crlf-injection', 'xml-injection', 'malicious-code', 'deserialization'], 'type': 'string', 'description': 'Filter by vulnerability category (reviewed only). One of: access-control, dos, xss, ssrf, auth, code-injection, info-exposure, path-traversal, input-validation, prototype-pollution, command-injection, sqli, crypto, race-condition, open-redirect, csrf, crlf-injection, xml-injection, malicious-code, deserialization'}, 'severity': {'enum': ['critical', 'high', 'medium', 'low', 'all'], 'type': 'string', 'description': 'Filter by severity (default all; not applicable to "malware"/"osv")'}, 'direction': {'enum': ['asc', 'desc'], 'type': 'string', 'description': 'Sort by published date, newest or oldest first (default desc)'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['type', 'severity', 'category', 'direction', 'nextCursor', 'advisories'], 'properties': {'type': {'enum': ['reviewed', 'malware', 'osv'], 'type': 'string'}, 'category': {'enum': ['all', 'access-control', 'dos', 'xss', 'ssrf', 'auth', 'code-injection', 'info-exposure', 'path-traversal', 'input-validation', 'prototype-pollution', 'command-injection', 'sqli', 'crypto', 'race-condition', 'open-redirect', 'csrf', 'crlf-injection', 'xml-injection', 'malicious-code', 'deserialization'], 'type': 'string'}, 'severity': {'enum': ['critical', 'high', 'medium', 'low', 'all'], 'type': 'string'}, 'direction': {'enum': ['asc', 'desc'], 'type': 'string'}, 'advisories': {'type': 'array', 'items': {'type': 'object', 'required': ['id', 'cve', 'summary', 'severity', 'publishedAt', 'ghsaUrl', 'npmscanUrl', 'cwes', 'categories', 'packages'], 'properties': {'id': {'type': 'string'}, 'cve': {'type': ['string', 'null']}, 'cwes': {'type': 'array', 'items': {'type': 'object', 'required': ['id', 'name'], 'properties': {'id': {'type': 'string'}, 'name': {'type': 'string'}}, 'additionalProperties': False}}, 'ghsaUrl': {'type': 'string'}, 'summary': {'type': 'string'}, 'packages': {'type': 'array', 'items': {'type': 'object', 'required': ['name', 'affectedRange', 'patchedVersion'], 'properties': {'name': {'type': 'string'}, 'affectedRange': {'type': ['string', 'null']}, 'patchedVersion': {'type': ['string', 'null']}}, 'additionalProperties': False}}, 'severity': {'type': 'string'}, 'categories': {'type': 'array', 'items': {'type': 'string'}}, 'npmscanUrl': {'type': 'string'}, 'publishedAt': {'type': 'string'}}, 'additionalProperties': False}}, 'nextCursor': {'type': ['string', 'null']}}, 'additionalProperties': False}
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['maintainerUsername'], 'properties': {'maintainerUsername': {'type': 'string', 'maxLength': 100, 'minLength': 1, 'description': 'Exact npm username, e.g. "sindresorhus" â\x80\x94 as shown at npmjs.com/~username. Not an email address, not a package name or scope.'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['maintainerUsername', 'npmscanUrl', 'npmProfileUrl', 'avatarUrl', 'totalPackagesFound', 'packagesReturned', 'resultsTruncated', 'currentlyMaintainsCount', 'totalWeeklyDownloads', 'totalDependents', 'packages', 'note'], 'properties': {'note': {'type': ['string', 'null']}, 'packages': {'type': 'array', 'items': {'type': 'object', 'required': ['name', 'version', 'lastPublished', 'weeklyDownloads', 'dependentsCount', 'isCurrentMaintainer', 'npmscanUrl'], 'properties': {'name': {'type': 'string'}, 'version': {'type': 'string'}, 'npmscanUrl': {'type': 'string'}, 'lastPublished': {'type': ['string', 'null']}, 'dependentsCount': {'type': ['number', 'null']}, 'weeklyDownloads': {'type': ['number', 'null']}, 'isCurrentMaintainer': {'type': 'boolean'}}, 'additionalProperties': False}}, 'avatarUrl': {'type': ['string', 'null']}, 'npmscanUrl': {'type': 'string'}, 'npmProfileUrl': {'type': 'string'}, 'totalDependents': {'type': 'number'}, 'packagesReturned': {'type': 'number'}, 'resultsTruncated': {'type': 'boolean'}, 'maintainerUsername': {'type': 'string'}, 'totalPackagesFound': {'type': 'number'}, 'totalWeeklyDownloads': {'type': 'number'}, 'currentlyMaintainsCount': {'type': 'number'}}, 'additionalProperties': False}
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['name'], 'properties': {'name': {'type': 'string', 'maxLength': 214, 'minLength': 1, 'description': 'Exact npm package name, e.g. "lodash" or "@scope/name"'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['name', 'description', 'license', 'homepage', 'repository', 'keywords', 'maintainers', 'distTags', 'latestVersion', 'latestVersionInfo', 'recentVersions', 'createdAt', 'modifiedAt', 'npmscanUrl', 'weeklyDownloads', 'githubStars', 'hasBuiltInTypes', 'daysSinceLastPublish', 'popularityTier', 'maintenanceTier', 'maintenanceSummary', 'topPackagesRank', 'downloadTrend', 'possibleTyposquatOf', 'isLatestVersionVulnerable', 'vulnerabilityCheckFailed', 'highestSeverity', 'vulnerabilities'], 'properties': {'name': {'type': 'string'}, 'license': {'type': ['string', 'null']}, 'distTags': {'type': 'object', 'additionalProperties': {'type': 'string'}}, 'homepage': {'type': ['string', 'null']}, 'keywords': {'type': 'array', 'items': {'type': 'string'}}, 'createdAt': {'type': ['string', 'null']}, 'modifiedAt': {'type': ['string', 'null']}, 'npmscanUrl': {'type': 'string'}, 'repository': {'type': ['string', 'null']}, 'description': {'type': ['string', 'null']}, 'githubStars': {'type': ['number', 'null']}, 'maintainers': {'type': 'array', 'items': {'type': 'object', 'required': ['name'], 'properties': {'name': {'type': 'string'}, 'email': {'type': 'string'}}, 'additionalProperties': False}}, 'downloadTrend': {'type': 'object', 'required': ['direction', 'changePercent'], 'properties': {'direction': {'enum': ['growing', 'stable', 'declining', 'unknown'], 'type': 'string'}, 'changePercent': {'type': ['number', 'null']}}, 'additionalProperties': False}, 'latestVersion': {'type': ['string', 'null']}, 'popularityTier': {'enum': ['very-high', 'high', 'moderate', 'low', 'very-low', 'unknown'], 'type': 'string'}, 'recentVersions': {'type': 'array', 'items': {'type': 'object', 'required': ['version', 'publishedAt'], 'properties': {'version': {'type': 'string'}, 'publishedAt': {'type': ['string', 'null']}}, 'additionalProperties': False}}, 'hasBuiltInTypes': {'type': 'boolean'}, 'highestSeverity': {'type': ['string', 'null']}, 'maintenanceTier': {'enum': ['active', 'aging', 'stale', 'unknown'], 'type': 'string'}, 'topPackagesRank': {'type': ['number', 'null']}, 'vulnerabilities': {'type': 'array', 'items': {'type': 'object', 'required': ['id', 'summary', 'severity', 'aliases', 'publishedAt', 'fixedVersion', 'npmscanUrl'], 'properties': {'id': {'type': 'string'}, 'aliases': {'type': 'array', 'items': {'type': 'string'}}, 'summary': {'type': ['string', 'null']}, 'severity': {'type': ['string', 'null']}, 'npmscanUrl': {'type': 'string'}, 'publishedAt': {'type': ['string', 'null']}, 'fixedVersion': {'type': ['string', 'null']}}, 'additionalProperties': False}}, 'weeklyDownloads': {'type': ['number', 'null']}, 'latestVersionInfo': {'anyOf': [{'type': 'object', 'required': ['version', 'dependencies', 'scripts', 'deprecated', 'tarball'], 'properties': {'scripts': {'type': 'object', 'additionalProperties': {'type': 'string'}}, 'tarball': {'type': ['string', 'null']}, 'version': {'type': 'string'}, 'deprecated': {'type': ['string', 'null']}, 'dependencies': {'type': 'object', 'additionalProperties': {'type': 'string'}}}, 'additionalProperties': False}, {'type': 'null'}]}, 'maintenanceSummary': {'type': 'string'}, 'possibleTyposquatOf': {'anyOf': [{'type': 'object', 'required': ['name', 'rank'], 'properties': {'name': {'type': 'string'}, 'rank': {'type': 'number'}}, 'additionalProperties': False}, {'type': 'null'}]}, 'daysSinceLastPublish': {'type': ['number', 'null']}, 'vulnerabilityCheckFailed': {'type': 'boolean'}, 'isLatestVersionVulnerable': {'type': 'boolean'}}, 'additionalProperties': False}
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['name', 'version'], 'properties': {'name': {'type': 'string', 'maxLength': 214, 'minLength': 1, 'description': 'Exact npm package name'}, 'version': {'type': 'string', 'maxLength': 128, 'minLength': 1, 'description': 'Exact version string, e.g. "4.17.21"'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['name', 'version', 'description', 'license', 'dependencies', 'scripts', 'deprecated', 'tarball', 'shasum', 'npmscanUrl', 'isVulnerable', 'vulnerabilityCheckFailed', 'highestSeverity', 'vulnerabilities'], 'properties': {'name': {'type': 'string'}, 'shasum': {'type': ['string', 'null']}, 'license': {'type': ['string', 'null']}, 'scripts': {'type': 'object', 'additionalProperties': {'type': 'string'}}, 'tarball': {'type': ['string', 'null']}, 'version': {'type': 'string'}, 'deprecated': {'type': ['string', 'null']}, 'npmscanUrl': {'type': 'string'}, 'description': {'type': ['string', 'null']}, 'dependencies': {'type': 'object', 'additionalProperties': {'type': 'string'}}, 'isVulnerable': {'type': 'boolean'}, 'highestSeverity': {'type': ['string', 'null']}, 'vulnerabilities': {'type': 'array', 'items': {'type': 'object', 'required': ['id', 'summary', 'severity', 'aliases', 'publishedAt', 'fixedVersion', 'npmscanUrl'], 'properties': {'id': {'type': 'string'}, 'aliases': {'type': 'array', 'items': {'type': 'string'}}, 'summary': {'type': ['string', 'null']}, 'severity': {'type': ['string', 'null']}, 'npmscanUrl': {'type': 'string'}, 'publishedAt': {'type': ['string', 'null']}, 'fixedVersion': {'type': ['string', 'null']}}, 'additionalProperties': False}}, 'vulnerabilityCheckFailed': {'type': 'boolean'}}, 'additionalProperties': False}
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'id': {'type': 'string', 'maxLength': 64, 'minLength': 1, 'description': 'A playbook slug to look up directly, e.g. "postinstall-binary" â\x80\x94 see /docs/playbooks'}, 'rules': {'type': 'array', 'items': {'type': 'string', 'maxLength': 64, 'minLength': 1}, 'maxItems': 10, 'minItems': 1, 'description': '1-10 exact `rule` values copied from findings already returned by analyze_install_script/check_maintainer_changes/check_package_provenance'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['matches', 'playbooks'], 'properties': {'matches': {'type': 'array', 'items': {'type': 'object', 'required': ['rule', 'requestedId', 'matched', 'playbookId', 'situationNote', 'note'], 'properties': {'note': {'type': 'string'}, 'rule': {'type': ['string', 'null']}, 'matched': {'type': 'boolean'}, 'playbookId': {'type': ['string', 'null']}, 'requestedId': {'type': ['string', 'null']}, 'situationNote': {'type': ['string', 'null']}}, 'additionalProperties': False}}, 'playbooks': {'type': 'array', 'items': {'type': 'object', 'required': ['id', 'title', 'severity', 'steps', 'references', 'preventionTips', 'npmscanUrl'], 'properties': {'id': {'type': 'string'}, 'steps': {'type': 'array', 'items': {'type': 'object', 'required': ['text', 'why'], 'properties': {'why': {'type': ['string', 'null']}, 'text': {'type': 'string'}}, 'additionalProperties': False}}, 'title': {'type': 'string'}, 'severity': {'enum': ['critical', 'high', 'moderate', 'low'], 'type': 'string'}, 'npmscanUrl': {'type': 'string'}, 'references': {'type': 'array', 'items': {'type': 'object', 'required': ['label', 'url', 'kind'], 'properties': {'url': {'type': 'string'}, 'kind': {'enum': ['incident', 'reading'], 'type': 'string'}, 'label': {'type': 'string'}}, 'additionalProperties': False}}, 'preventionTips': {'type': 'array', 'items': {'type': 'string'}}}, 'additionalProperties': False}}}, 'additionalProperties': False}
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['findings'], 'properties': {'findings': {'type': 'array', 'items': {'type': 'object', 'required': ['packageName'], 'properties': {'cveId': {'type': 'string', 'pattern': '^CVE-\\d{4}-\\d{4,}$', 'description': 'Exact CVE ID, e.g. "CVE-2024-12345" â\x80\x94 enables CISA KEV + FIRST.org EPSS enrichment. Omit for a GHSA advisory with no CVE alias; the finding is still ranked by severity alone.'}, 'severity': {'type': 'string', 'maxLength': 32, 'description': 'Severity from the source finding (OSV/GHSA: CRITICAL/HIGH/MODERATE/LOW, or NVD: CRITICAL/HIGH/MEDIUM/LOW) â\x80\x94 used as a fallback/secondary signal'}, 'advisoryId': {'type': 'string', 'maxLength': 64, 'description': 'GHSA/OSV advisory id, passed through unchanged for reference â\x80\x94 a MAL-* id is auto-detected as malware even without findingType set'}, 'findingType': {'enum': ['malware', 'vulnerability', 'supply-chain', 'install-script'], 'type': 'string', 'description': '"malware" forces the remove-now tier regardless of score/CVE/severity â\x80\x94 set this (or pass a MAL-* advisoryId) for a confirmed-malicious package. Omit for an ordinary vulnerability finding.'}, 'packageName': {'type': 'string', 'maxLength': 214, 'minLength': 1, 'description': 'npm package name this finding was flagged against'}, 'fixedVersion': {'type': 'string', 'maxLength': 128, 'description': 'Version that fixes this finding, passed through unchanged'}, 'currentVersion': {'type': 'string', 'maxLength': 128, 'description': 'Currently installed version, passed through unchanged'}}, 'additionalProperties': False}, 'maxItems': 200, 'minItems': 1, 'description': '1-200 previously-flagged vulnerability findings to rank'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['totalFindings', 'uniqueCveCount', 'summary', 'ranked'], 'properties': {'ranked': {'type': 'array', 'items': {'type': 'object', 'required': ['rank', 'packageName', 'cveId', 'advisoryId', 'currentVersion', 'fixedVersion', 'severity', 'kev', 'epss', 'score', 'tier', 'findingType', 'reason', 'npmscanUrl', 'cveNpmscanUrl'], 'properties': {'kev': {'anyOf': [{'type': 'object', 'required': ['dateAdded', 'dueDate', 'knownRansomwareCampaignUse', 'requiredAction'], 'properties': {'dueDate': {'type': 'string'}, 'dateAdded': {'type': 'string'}, 'requiredAction': {'type': 'string'}, 'knownRansomwareCampaignUse': {'type': 'string'}}, 'additionalProperties': False}, {'type': 'null'}]}, 'epss': {'anyOf': [{'type': 'object', 'required': ['score', 'percentile', 'date'], 'properties': {'date': {'type': 'string'}, 'score': {'type': 'number'}, 'percentile': {'type': 'number'}}, 'additionalProperties': False}, {'type': 'null'}]}, 'rank': {'type': 'number'}, 'tier': {'enum': ['remove-now', 'patch-now', 'patch-soon', 'scheduled', 'monitor'], 'type': 'string'}, 'cveId': {'type': ['string', 'null']}, 'score': {'type': 'number'}, 'reason': {'type': 'string'}, 'severity': {'type': ['string', 'null']}, 'advisoryId': {'type': ['string', 'null']}, 'npmscanUrl': {'type': 'string'}, 'findingType': {'enum': ['malware', 'vulnerability', 'supply-chain', 'install-script'], 'type': 'string'}, 'packageName': {'type': 'string'}, 'fixedVersion': {'type': ['string', 'null']}, 'cveNpmscanUrl': {'type': ['string', 'null']}, 'currentVersion': {'type': ['string', 'null']}}, 'additionalProperties': False}}, 'summary': {'type': 'object', 'required': ['removeNow', 'patchNow', 'patchSoon', 'scheduled', 'monitor', 'kevListedCount'], 'properties': {'monitor': {'type': 'number'}, 'patchNow': {'type': 'number'}, 'patchSoon': {'type': 'number'}, 'removeNow': {'type': 'number'}, 'scheduled': {'type': 'number'}, 'kevListedCount': {'type': 'number'}}, 'additionalProperties': False}, 'totalFindings': {'type': 'number'}, 'uniqueCveCount': {'type': 'number'}}, 'additionalProperties': False}
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['name'], 'properties': {'name': {'type': 'string', 'maxLength': 214, 'minLength': 1, 'description': 'npm package name'}, 'version': {'type': 'string', 'maxLength': 128, 'description': 'Optional exact version to narrow results, e.g. to check one version pinned in a lockfile'}, 'ecosystem': {'type': 'string', 'maxLength': 32, 'description': 'OSV ecosystem, default "npm"'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['package', 'version', 'npmscanUrl', 'packageExists', 'existenceCheckNote', 'isVulnerable', 'highestSeverity', 'vulnerabilities'], 'properties': {'package': {'type': 'string'}, 'version': {'type': ['string', 'null']}, 'npmscanUrl': {'type': 'string'}, 'isVulnerable': {'type': 'boolean'}, 'packageExists': {'type': ['boolean', 'null']}, 'highestSeverity': {'type': ['string', 'null']}, 'vulnerabilities': {'type': 'array', 'items': {'type': 'object', 'required': ['id', 'summary', 'severity', 'aliases', 'publishedAt', 'fixedVersion', 'npmscanUrl'], 'properties': {'id': {'type': 'string'}, 'aliases': {'type': 'array', 'items': {'type': 'string'}}, 'summary': {'type': ['string', 'null']}, 'severity': {'type': ['string', 'null']}, 'npmscanUrl': {'type': 'string'}, 'publishedAt': {'type': ['string', 'null']}, 'fixedVersion': {'type': ['string', 'null']}}, 'additionalProperties': False}}, 'existenceCheckNote': {'type': ['string', 'null']}}, 'additionalProperties': False}
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['query'], 'properties': {'limit': {'type': 'integer', 'maximum': 50, 'minimum': 1, 'description': 'Max results to return (default 20, max 50)'}, 'query': {'type': 'string', 'maxLength': 64, 'minLength': 2, 'description': 'Search text, e.g. a package name or keywords'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['query', 'total', 'results'], 'properties': {'query': {'type': 'string'}, 'total': {'type': 'number'}, 'results': {'type': 'array', 'items': {'type': 'object', 'required': ['name', 'version', 'description', 'keywords', 'publisher', 'lastPublished', 'links', 'npmscanUrl', 'weeklyDownloads', 'monthlyDownloads', 'dependentsCount', 'topPackagesRank', 'popularityTier', 'maintenanceTier', 'possibleTyposquatOf'], 'properties': {'name': {'type': 'string'}, 'links': {'type': 'object', 'properties': {'npm': {'type': 'string'}, 'homepage': {'type': 'string'}, 'repository': {'type': 'string'}}, 'additionalProperties': False}, 'version': {'type': 'string'}, 'keywords': {'type': 'array', 'items': {'type': 'string'}}, 'publisher': {'type': ['string', 'null']}, 'npmscanUrl': {'type': 'string'}, 'description': {'type': ['string', 'null']}, 'lastPublished': {'type': ['string', 'null']}, 'popularityTier': {'enum': ['very-high', 'high', 'moderate', 'low', 'very-low', 'unknown'], 'type': 'string'}, 'dependentsCount': {'type': ['number', 'null']}, 'maintenanceTier': {'enum': ['active', 'aging', 'stale', 'unknown'], 'type': 'string'}, 'topPackagesRank': {'type': ['number', 'null']}, 'weeklyDownloads': {'type': ['number', 'null']}, 'monthlyDownloads': {'type': ['number', 'null']}, 'possibleTyposquatOf': {'anyOf': [{'type': 'object', 'required': ['name', 'rank'], 'properties': {'name': {'type': 'string'}, 'rank': {'type': 'number'}}, 'additionalProperties': False}, {'type': 'null'}]}}, 'additionalProperties': False}}}, 'additionalProperties': False}
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'packages': {'type': 'array', 'items': {'type': 'object', 'required': ['packageName', 'currentVersion'], 'properties': {'packageName': {'type': 'string', 'maxLength': 214, 'minLength': 1, 'description': 'Exact npm package name, e.g. "lodash" or "@scope/name"'}, 'targetVersion': {'type': 'string', 'maxLength': 128, 'minLength': 1, 'description': 'Version to simulate upgrading to â\x80\x94 exact version, range, or dist-tag. Omit to use the registry\'s "latest" dist-tag.'}, 'currentVersion': {'type': 'string', 'maxLength': 128, 'minLength': 1, 'description': 'Currently installed version â\x80\x94 an exact version, a semver range, or a dist-tag'}}, 'additionalProperties': False}, 'maxItems': 100, 'minItems': 1, 'description': 'Batch of upgrades to simulate (1-100 items), each mirroring the single-item packageName/currentVersion/targetVersion fields. Use this OR packageName/currentVersion, not both. Natural pairing with prioritize_remediation: pass its ranked findings straight in as one call instead of one simulate_dependency_upgrade call per finding.'}, 'packageName': {'type': 'string', 'maxLength': 214, 'minLength': 1, 'description': 'Exact npm package name, e.g. "lodash" or "@scope/name". Use this (with currentVersion) OR `packages`, not both.'}, 'targetVersion': {'type': 'string', 'maxLength': 128, 'minLength': 1, 'description': 'Version to simulate upgrading to â\x80\x94 exact version, range, or dist-tag (e.g. the fixedVersion a prioritize_remediation finding named). Omit to use the registry\'s "latest" dist-tag. Only applies to the single-item `packageName` form.'}, 'currentVersion': {'type': 'string', 'maxLength': 128, 'minLength': 1, 'description': 'Currently installed version â\x80\x94 an exact version (e.g. "4.17.20"), a semver range (e.g. "^4.17.0"), or a dist-tag. Required when `packageName` is used.'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'reasons': {'type': 'array', 'items': {'type': 'string'}}, 'results': {'type': 'array', 'items': {'type': 'object', 'required': ['packageName', 'npmscanUrl', 'requestedCurrentVersion', 'requestedTargetVersion', 'resolvedCurrentVersion', 'resolvedTargetVersion', 'currentVersionNote', 'targetVersionNote', 'direction', 'semverBump', 'isBreakingBySemver', 'majorVersionsSkipped', 'zeroMajorNote', 'targetIsPrerelease', 'targetDeprecated', 'installScriptIntroduced', 'engineChange', 'currentIsVulnerable', 'targetIsVulnerable', 'vulnerabilityDelta', 'targetVulnerabilities', 'riskTier', 'reasons', 'verdict', 'fetchError'], 'properties': {'reasons': {'type': 'array', 'items': {'type': 'string'}}, 'verdict': {'type': 'string'}, 'riskTier': {'enum': ['safe', 'low-risk', 'review-recommended', 'breaking-change-likely', 'unknown'], 'type': 'string'}, 'direction': {'enum': ['upgrade', 'downgrade', 'same', 'unresolved'], 'type': 'string'}, 'fetchError': {'type': ['string', 'null']}, 'npmscanUrl': {'type': 'string'}, 'semverBump': {'anyOf': [{'enum': ['major', 'premajor', 'minor', 'preminor', 'patch', 'prepatch', 'prerelease'], 'type': 'string'}, {'type': 'null'}]}, 'packageName': {'type': 'string'}, 'engineChange': {'anyOf': [{'type': 'object', 'required': ['before', 'after', 'tightened'], 'properties': {'after': {'type': ['string', 'null']}, 'before': {'type': ['string', 'null']}, 'tightened': {'type': 'boolean'}}, 'additionalProperties': False}, {'type': 'null'}]}, 'zeroMajorNote': {'type': ['string', 'null']}, 'targetDeprecated': {'type': ['string', 'null']}, 'targetVersionNote': {'type': ['string', 'null']}, 'currentVersionNote': {'type': ['string', 'null']}, 'isBreakingBySemver': {'type': ['boolean', 'null']}, 'targetIsPrerelease': {'type': ['boolean', 'null']}, 'targetIsVulnerable': {'type': ['boolean', 'null']}, 'vulnerabilityDelta': {'anyOf': [{'enum': ['introduced', 'fixed', 'still-vulnerable', 'still-clean', 'unknown'], 'type': 'string'}, {'type': 'null'}]}, 'currentIsVulnerable': {'type': ['boolean', 'null']}, 'majorVersionsSkipped': {'type': ['number', 'null']}, 'resolvedTargetVersion': {'type': ['string', 'null']}, 'targetVulnerabilities': {'type': 'array', 'items': {'$ref': '#/properties/targetVulnerabilities/items'}}, 'requestedTargetVersion': {'type': 'string'}, 'resolvedCurrentVersion': {'type': ['string', 'null']}, 'installScriptIntroduced': {'type': ['boolean', 'null']}, 'requestedCurrentVersion': {'type': 'string'}}, 'additionalProperties': False}}, 'verdict': {'type': 'string'}, 'riskTier': {'enum': ['safe', 'low-risk', 'review-recommended', 'breaking-change-likely', 'unknown'], 'type': 'string'}, 'direction': {'enum': ['upgrade', 'downgrade', 'same', 'unresolved'], 'type': 'string'}, 'npmscanUrl': {'type': 'string'}, 'semverBump': {'anyOf': [{'enum': ['major', 'premajor', 'minor', 'preminor', 'patch', 'prepatch', 'prerelease'], 'type': 'string'}, {'type': 'null'}]}, 'packageName': {'type': 'string'}, 'batchSummary': {'type': 'object', 'required': ['totalRequested', 'fetchFailedCount', 'riskTierCounts', 'vulnQueryFailedCount'], 'properties': {'riskTierCounts': {'type': 'object', 'required': ['safe', 'lowRisk', 'reviewRecommended', 'breakingChangeLikely', 'unknown'], 'properties': {'safe': {'type': 'number'}, 'lowRisk': {'type': 'number'}, 'unknown': {'type': 'number'}, 'reviewRecommended': {'type': 'number'}, 'breakingChangeLikely': {'type': 'number'}}, 'additionalProperties': False}, 'totalRequested': {'type': 'number'}, 'fetchFailedCount': {'type': 'number'}, 'vulnQueryFailedCount': {'type': 'number'}}, 'additionalProperties': False}, 'engineChange': {'anyOf': [{'type': 'object', 'required': ['before', 'after', 'tightened'], 'properties': {'after': {'type': ['string', 'null']}, 'before': {'type': ['string', 'null']}, 'tightened': {'type': 'boolean'}}, 'additionalProperties': False}, {'type': 'null'}]}, 'zeroMajorNote': {'type': ['string', 'null']}, 'targetDeprecated': {'type': ['string', 'null']}, 'targetVersionNote': {'type': ['string', 'null']}, 'currentVersionNote': {'type': ['string', 'null']}, 'isBreakingBySemver': {'type': ['boolean', 'null']}, 'targetIsPrerelease': {'type': ['boolean', 'null']}, 'targetIsVulnerable': {'type': ['boolean', 'null']}, 'vulnerabilityDelta': {'anyOf': [{'enum': ['introduced', 'fixed', 'still-vulnerable', 'still-clean', 'unknown'], 'type': 'string'}, {'type': 'null'}]}, 'currentIsVulnerable': {'type': ['boolean', 'null']}, 'majorVersionsSkipped': {'type': ['number', 'null']}, 'resolvedTargetVersion': {'type': ['string', 'null']}, 'targetVulnerabilities': {'type': 'array', 'items': {'type': 'object', 'required': ['id', 'summary', 'severity', 'aliases', 'publishedAt', 'fixedVersion', 'npmscanUrl'], 'properties': {'id': {'type': 'string'}, 'aliases': {'type': 'array', 'items': {'type': 'string'}}, 'summary': {'type': ['string', 'null']}, 'severity': {'type': ['string', 'null']}, 'npmscanUrl': {'type': 'string'}, 'publishedAt': {'type': ['string', 'null']}, 'fixedVersion': {'type': ['string', 'null']}}, 'additionalProperties': False}}, 'requestedTargetVersion': {'type': 'string'}, 'resolvedCurrentVersion': {'type': ['string', 'null']}, 'installScriptIntroduced': {'type': ['boolean', 'null']}, 'requestedCurrentVersion': {'type': 'string'}}, 'additionalProperties': False}
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['name'], 'properties': {'name': {'type': 'string', 'maxLength': 214, 'minLength': 1, 'description': 'Exact npm package name, e.g. "request" or "node-sass"'}, 'limit': {'type': 'integer', 'maximum': 10, 'minimum': 1, 'description': 'Max suggestions to return (default 5, max 10)'}, 'reason': {'enum': ['deprecated', 'vulnerable', 'abandoned', 'typosquat', 'general'], 'type': 'string', 'description': 'Optional reason to bias filtering/ranking'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['source', 'reason', 'confidence', 'categoryTokens', 'searchedQueries', 'nonPackageAlternatives', 'suggestions'], 'properties': {'reason': {'enum': ['deprecated', 'vulnerable', 'abandoned', 'typosquat', 'general'], 'type': 'string'}, 'source': {'type': 'object', 'required': ['name', 'latestVersion', 'deprecated', 'isLatestVersionVulnerable', 'vulnerabilityCheckFailed', 'highestSeverity', 'popularityTier', 'maintenanceTier', 'possibleTyposquatOf', 'npmscanUrl'], 'properties': {'name': {'type': 'string'}, 'deprecated': {'type': ['string', 'null']}, 'npmscanUrl': {'type': 'string'}, 'latestVersion': {'type': ['string', 'null']}, 'popularityTier': {'enum': ['very-high', 'high', 'moderate', 'low', 'very-low', 'unknown'], 'type': 'string'}, 'highestSeverity': {'type': ['string', 'null']}, 'maintenanceTier': {'enum': ['active', 'aging', 'stale', 'unknown'], 'type': 'string'}, 'possibleTyposquatOf': {'anyOf': [{'type': 'object', 'required': ['name', 'rank'], 'properties': {'name': {'type': 'string'}, 'rank': {'type': 'number'}}, 'additionalProperties': False}, {'type': 'null'}]}, 'vulnerabilityCheckFailed': {'type': 'boolean'}, 'isLatestVersionVulnerable': {'type': 'boolean'}}, 'additionalProperties': False}, 'confidence': {'enum': ['high', 'medium', 'low'], 'type': 'string'}, 'suggestions': {'type': 'array', 'items': {'type': 'object', 'required': ['name', 'version', 'description', 'npmscanUrl', 'weeklyDownloads', 'dependentsCount', 'githubStars', 'hasBuiltInTypes', 'deprecated', 'isLatestVersionVulnerable', 'vulnerabilityCheckFailed', 'highestSeverity', 'popularityTier', 'maintenanceTier', 'topPackagesRank', 'categoryOverlap', 'matchedQueries', 'whySuggested'], 'properties': {'name': {'type': 'string'}, 'version': {'type': ['string', 'null']}, 'deprecated': {'type': ['string', 'null']}, 'npmscanUrl': {'type': 'string'}, 'description': {'type': ['string', 'null']}, 'githubStars': {'type': ['number', 'null']}, 'whySuggested': {'type': 'string'}, 'matchedQueries': {'type': 'array', 'items': {'type': 'string'}}, 'popularityTier': {'enum': ['very-high', 'high', 'moderate', 'low', 'very-low', 'unknown'], 'type': 'string'}, 'categoryOverlap': {'type': 'array', 'items': {'type': 'string'}}, 'dependentsCount': {'type': ['number', 'null']}, 'hasBuiltInTypes': {'type': 'boolean'}, 'highestSeverity': {'type': ['string', 'null']}, 'maintenanceTier': {'enum': ['active', 'aging', 'stale', 'unknown'], 'type': 'string'}, 'topPackagesRank': {'type': ['number', 'null']}, 'weeklyDownloads': {'type': ['number', 'null']}, 'vulnerabilityCheckFailed': {'type': 'boolean'}, 'isLatestVersionVulnerable': {'type': 'boolean'}}, 'additionalProperties': False}}, 'categoryTokens': {'type': 'array', 'items': {'type': 'string'}}, 'searchedQueries': {'type': 'array', 'items': {'type': 'string'}}, 'nonPackageAlternatives': {'type': 'array', 'items': {'type': 'string'}}}, 'additionalProperties': False}
Letzte Tool-Änderungen
Ähnliche MCP-Server
hyperion
Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…
Vee3
Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…
IA-QA — 130+ QA & Dev Tools for AI Agents
Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…
validoria-mcp
Runs continuous website, API, and webshop tests covering security, SEO, performance, accessibility, browser journeys, and inciden…
HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data
Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…
developer-tools
Provides general-purpose developer utilities for encoding, hashing, encryption, JSON, HTML, CSS, networking, and related data tra…
Qiniso
Provides deterministic formatting, parsing, holiday and tax lookups, address handling, and checksum or structure validation for i…
ContrastAPI
Provides security research and assessment tools covering CVEs, IOCs, dependencies, secrets, injection risks, HTTP headers, domain…