Check package.json for vulnerabilities
check_package_jsonUse this when the user asks to check their package.json, or the dependencies of a project, for known vulnerabilities: "check my package.json for known vulnerabilities". Pass the text of the package.json; only the names and versions in dependencies, devDependencies and optionalDependencies are read, nothing else in the file is used or kept, and nothing is stored. Do not ask for source code or tokens. Checks up to 150 npm dependencies at the version each names (ranges at their lowest version) and returns the vulnerable ones, most severe first, with the fixed version. Dependencies without an exact version (tags, urls, workspaces) are listed as skipped.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| packageJson | Yes | The text of the user's package.json. Only its dependency names and versions are read. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| status | Yes | ||
| checked | Yes | Dependencies looked up | |
| message | No | ||
| skipped | Yes | Dependencies without an exact version, not looked up | |
| truncated | Yes | ||
| cleanCount | Yes | Looked up with no known vulnerability | |
| skippedCount | Yes | ||
| vulnerablePackages | Yes |