audit
Scan your dependencies for known vulnerabilities.
Checks your project's dependencies against the OSV.dev vulnerability database (npm, crates.io, Go, PyPI and Packagist) and tells you what to fix. Findings are ranked by whether they can actually hurt you: production dependencies keep full severity, dev-only tools are downgraded, and deep transitive noise is grouped so the report stays readable. One repo, or every repo you have.