@vctools/security
v0.1.0
Published
Security Scanner — wraps Semgrep with the OWASP Top 10 ruleset for vibe-coded projects.
Maintainers
Readme
@vctools/security
Security Scanner — wraps Semgrep with the OWASP Top 10 ruleset. Maps Semgrep ERROR/WARNING/INFO findings to vctools' critical/high/medium severity scale, blocks deploy on any critical (configurable).
Requires pip install semgrep on your PATH.
Most users want @vctools/cli and the vctools scan-security command.
vctools scan-security .Honours .vctools/security.json for ignored paths, ignored rules, and block thresholds.
Source: github.com/FaraiMacheka/vctools
License
MIT
