{"repo":"BARMPlus/locklens","free":true,"listed":false,"github":"https://github.com/BARMPlus/locklens","clone":"git clone https://github.com/BARMPlus/locklens.git","description":"Audit npm, Yarn, and pnpm lockFiles as both an MCP server and a CLI tool.","language":"TypeScript","stars":85,"topics":["audit","frontend","mcp","npm","pnpm","yarn"],"license":"MIT","category":"mcp-servers","readme_excerpt":"locklens locklens 是一个基于 audit-ci 的 lockfile 审计工具，支持三种运行模式： - CLI / npx - MCP Server（ stdio ） - Skill 它可以审计本地项目目录或远程 Git 仓库，并支持 npm 、 yarn 、 pnpm 的 lockfile。 --- 特性 - 支持本地项目目录与远程 Git 仓库审计 - 支持公开仓库与私有仓库审计 - 支持 package-lock.json 、 yarn.lock 、 pnpm-lock.yaml - 仅基于仓库中已存在的 lockFile 进行审计，保证结果与真实依赖状态一致 - 支持中文、英文文本报告 - 支持显式切换为 JSON 输出 --- 环境要求 - Node =18 - (Optional) Yarn ^1.12.3 Yarn =2.4.0 && =4.3.0 - (Optional) Bun --- 结果示例 可以直接查看仓库内的示例输出： - 中文文本报告示例：audit.md - 英文文本报告示例：audit-en US.md - JSON 输出示例：audit.json --- 安装与环境 本地仓库、线上仓库审计： 私有仓库审计： --- CLI 使用方法 常见示例 输出英文文本报告： 输出 JSON： 指定阈值为高危： 跳过 devDependencies： CLI 参数 参数 说明 --- --- --source 必填。本地目录路径或远程 Git 仓库地址 --threshold 漏洞过滤阈值，可选： low 、 moderate 、 high 、 critical ，默认： low --registry 自定义 npm registry，默认： https://registry.npmjs.org/ --skip-dev 跳过 dev dependencies --retry-count 审计执行重试次数 --output-format 输出格式，可选： json 、 text ，默认： text --output-format-language 文本报告语言，可选： zh 、 en ，默认： zh --help / -h 显示帮助 --version / -v 显示版本号 --- MCP 使用方法 locklens 支持通过 stdio 方式作为 MCP Server 接入，通过将以下配置添加到mcp服务器配置中。 Windows 平台： 其他平台： Tools package audit 审计指定项目目录或远程 Git 仓库的 lockfile，并返回统一格式的漏洞结果。 参数： - source - 必填。本地目录绝对路径，或远程 Git 仓库地址 - threshold - 漏洞过滤阈值，可选： low 、 moderate 、 high 、 critical ；默认： low - registry - 自定义 npm registry 地址；默认： https://registry.npmjs.org/ - skipDev - 是否跳过 dev dependencies - retryCount - 审计执行重试次数 - outputFormat - 输出格式，可选： text 、 json ；默认： text - outputFormatLanguage - 文本报告语言，可选： zh 、 en ；默认： zh --- Skill 如果你的客户端支持 Skill，也可以直接使用 dependency","default_branch":null,"files":null,"tree":[],"storefront":"/r/BARMPlus","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/BARMPlus/locklens/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}