Matchboxmatchbox
← Back to match

CVE Lite CLI

Local JS/TS dependency vulnerability scanner that gives copy-and-run fix commands.

Desktopfreeglobal

A local command-line scanner for JavaScript and TypeScript projects that analyzes lockfiles against OSV data and produces validated copy-and-run fix commands instead of just CVE identifiers. It highlights direct versus transitive risk, checks npm/pnpm/Yarn/Bun override and resolution hygiene, and is aimed at developers and application security engineers who need actionable remediation steps without sending code off-machine; it is recognized as an OWASP Lab Project.

Categories
dependency scanningvulnerability managementdeveloper tools

Full match profile

Behind the summary, Matchbox keeps a richer profile of CVE Lite CLI - the signals our matcher actually reads to decide when to surface it. It stays private; claim the listing to see and control it.

  • Problem & pain-point mapping
  • Who we surface it to (audience fit)
  • What it's a strong alternative to
  • Trust & credibility signals

Try Matchbox with your own problem

Describe what is not working - we’ll show you whether CVE Lite CLI (or something else) actually fits.