NPMScan
Automated github dependency security scanner
#Software Engineering
#GitHub
#Security
SUMMARY
NPMScan is a dashboard tool designed to scan GitHub repositories for package.json files, highlighting vulnerable or outdated npm dependencies and prioritizing critical vulnerabilities. It aggregates node package versions across all repositories, providing a single interface for prioritizing and triaging security issues. Key features include aggregation of all repositories into one dashboard, prioritization through health scores, and a quick 30-second setup. NPMScan aims to reduce the noise created by multiple Dependabot PRs and streamline dependency management. It is free to start and seeks feedback from Tech Leads and Security Engineers.