About this project
npm-script-lens is a security-focused CLI tool designed to help developers audit and approve dependency lifecycle scripts (preinstall, install, postinstall) and native builds. As modern package managers move toward opt-in execution models, this tool provides evidence-based analysis to determine which packages are safe to run. It performs static analysis on scripts using acorn, inspects binding.gyp files for hidden execution channels, and identifies runtime bootstrapping techniques (e.g., downloading external runtimes like Bun or Deno). The tool integrates with CI/CD pipelines to enforce security policies, such as failing on high-risk behaviors, malicious package detection via OSV, or insufficient package age (cooldown). It also provides provenance verification to ensure that installed artifacts match the expected source repository and workflow. Additionally, it includes utilities for managing git and remote dependency configurations, ensuring compliance with npm v12+ security requirements. Results can be exported as JSON, HTML, or SARIF reports for integration with security scanning tools.
Comments
0 people shared their preference · Deer Point appears after 10 participants
Sign in to join the discussion.