{"repo":"lirantal/npq","free":true,"listed":false,"github":"https://github.com/lirantal/npq","clone":"git clone https://github.com/lirantal/npq.git","description":"safely install npm packages by auditing them pre-install stage","language":"JavaScript","stars":1783,"topics":["npm","package-manager","security-audit","command-line-tool","vulnerabilities","security","security-tools","appsec","vulnerability-scanners","best-practices"],"license":"Apache-2.0","category":"cli-tools","readme_excerpt":"npq allows you to audit npm packages before you install them TL;DR how to use npq: What it does: the npx tool downloads and execute npq package, runs an install check for the express package and --dry-run means npq exists regardless of success/errors . Here's a screenshot of npq in action: Media coverage about npq: - As mentioned on Thomas Gentilhomme's French book of Become a Node.js Developer - Tao Bojlén's A web of trust for npm - Zander's favorite list of command line tools - Ran Bar Zik's npq review to install safe modules - ostechnix's How To Safely Install Packages Using Npm Or Yarn On Linux - debricked's How to evaluate the security of your NPM Package dependencies - JavaScript January advent calendar's post on Open Source From Heaven, Modules From Hell - Liran Tal's Malicious Modules — what you need to know when installing npm packages About Once npq is installed, you can safely install packages: npq will perform the following steps to sanity check that the package is safe by employing syntactic heuristics and querying a CVE database: Consult the snyk.io database of publicly disclosed vulnerabilities to check if a security vulnerability exists for this package and its version. Package age on npm Package download count as a popularity metric Package has a README file Package has a LICENSE file Package has pre/post install scripts IMPORTANT : npq by default uses an auto-continue mode when warnings are detected (no errors), waiting 15 seconds before proceeding with the ","default_branch":null,"files":null,"tree":[],"storefront":"/r/lirantal","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/lirantal/npq/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}