Skip to content

Open Source Friday - CVE Lite CLI - 09-18-2026 #250

Description

@sonukapoor

Name

Sonu Kapoor

GitHub Handle

@sonukapoor

Tell us about yourself

I'm a developer and open source maintainer focused on application security tooling. I created CVE Lite CLI, a dependency vulnerability scanner for JavaScript and TypeScript projects that's now an OWASP Lab Project. I've been building in public since March 2026 - the project hit close to 50K+ npm downloads in under four months and has been covered by The Register, SD Times, SecurityWeek, CSO Online, and Help Net Security.

Project Name

CVE Lite CLI

Project Repo Link

https://github.com/OWASP/cve-lite-cli

Stream Date

  • Yes
  • Not yet

Dates

18 Sep 2026

Twitter URL

@SonuKapoor1978

LinkedIn URL

https://www.linkedin.com/in/sonu-kapoor/

Additional Information

CVE Lite CLI is a fast, local dependency vulnerability scanner for npm, pnpm, Yarn, and Bun projects. It classifies every finding as direct or transitive, validates fix versions against OSV before recommending them, and gives developers the exact upgrade command to run - not just a list of advisory IDs. It runs entirely locally; no login or API key required.

It graduated as an OWASP Lab Project in June 2026 and has been adopted by teams across fintech, government, and developer tooling - including French government ministries and organizations in the US, Canada, Portugal, and Brazil. I'd love to walk through how it works, what makes it different from npm audit and Dependabot, and where the project is headed.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions