{"repo":"Wahid7852/trawld","free":true,"listed":false,"github":"https://github.com/Wahid7852/trawld","clone":"git clone https://github.com/Wahid7852/trawld.git","description":"Package vulnerability monitoring for developer fleets - auto-discovers projects, scans dependencies against OSV, and streams live alerts to a real-time dashboard.","language":"JavaScript","stars":11,"topics":["security","vulnerability-scanner","dependencies","devtools","monitoring","npm","osv","dashboard","mongodb","nodejs"],"license":"MIT","category":"security-tools","readme_excerpt":"trawld Package vulnerability monitoring for developer fleets. trawld watches every enrolled machine, discovers projects automatically, and surfaces vulnerable dependencies in a real-time dashboard - no code changes to your apps required. How it works 1. Deploy the Cloud Brain once (Vercel + MongoDB). 2. Enroll machines by running trawld setup . 3. Open the dashboard - packages are indexed, vulnerabilities matched against the OSV database, and heartbeats keep online/offline status live. Components - Cloud Brain - React dashboard + REST API, deploys to Vercel, persists to MongoDB. - trawld Agent - global npm package, setup wizard, passive project discovery, scheduled rescans, heartbeats. - Runtime Node Hook - optional package for PID-aware process registration inside Node apps. Architecture Quick Start Deploy the Cloud Brain 1. Create a MongoDB database. 2. Deploy cloud/ to Vercel. 3. Set environment variables: Enroll a Machine The setup wizard connects to your Cloud Brain, picks project folders to watch, and optionally configures startup. Done - the machine appears in your dashboard. Open Enrollment Any machine that can reach your Cloud Brain URL can enroll without a token. The agent sends machine metadata to POST /api/agents/enroll and gets back a session ID. All future inventory and heartbeat calls use that ID. This keeps onboarding frictionless. If you need tighter access control later, add invite tokens or an IP allowlist at the reverse-proxy level. Local Development start","default_branch":null,"files":null,"tree":[],"storefront":"/r/Wahid7852","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Wahid7852/trawld/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}