Supply Chain
Check your dependencies for known vulnerabilities.
Paste your package.json and we'll query OSV.dev — Google's open vulnerability database — for every pinned dependency, then show severity, affected versions, and the release that fixes each issue.
Only package names and versions are checked against OSV.dev. We do not store your manifest.
- Backed by OSV.dev, the same data source used by GitHub and Google.
- Direct dependencies only — transitive packages need a lockfile scan.
- Your manifest is used for the lookup and not stored.
Want this done properly, across your whole estate?
A free tool finds the obvious. Our team finds what it misses.