carrot-scan
Command-line tool for detecting vulnerabilities in files and directories.
reproduce
Validate a package's reproducibility against it's published repository information.
license-checker-evergreen
NPM license audit and dependency compliance checker - Scan, validate, and analyze open source licenses with SPDX validation. Feature-enhanced, TypeScript-based fork of license-checker with better performance and reliability.
pkg-health
A CLI tool to scan your project's dependencies and generate a health report with security, version, and license insights.