npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

crawatch

v1.0.1

Published

Fail the build when a dependency in your lockfile is on the CISA Known Exploited Vulnerabilities list. Scans against OSV too. Free, no account, no token. For the EU Cyber Resilience Act's 24-hour reporting clock.

Downloads

351

Readme

crawatch

Fail the build when a dependency you ship is on CISA's Known Exploited Vulnerabilities list.

One command, no account, no token, no dependencies. Works on 19 lockfile formats and on CycloneDX or SPDX SBOMs.

npx crawatch package-lock.json
package-lock.json: npm, 1 package(s), 18 known vulnerabilities, 1 on the CISA exploited list
  KEV  [email protected]  CVE-2025-31125  listed 2026-01-22  fixed in 4.5.11
       [email protected]  CVE-2024-23331  severity 7.5  fixed in 4.5.2
       ...
  share https://crawatch.dev/r/1bpOHVu2yOPE7NDAg5R9n
  Under CRA Article 14 the 24-hour early warning runs from when you become aware. That may be now: https://crawatch.dev/docs/cra-first-24-hours

Why the exploited list, and not every CVE

A typical lockfile carries dozens of advisories. Almost none of them are being exploited. The ones on CISA's KEV catalog are: an attacker has used them, in the wild, with evidence. Over the last twelve months that was 33 CVEs in open-source packages, about three a month (litellm, n8n and drupal/core among them; the full list).

That short list is the one worth failing a build over. It is also the one that matters legally. Since 11 September 2026, Article 14 of the EU Cyber Resilience Act requires anyone who sells software in the EU to report an actively exploited vulnerability in their product to ENISA within 24 hours of becoming aware of it. A dependency counts as part of your product.

So crawatch fails on KEV by default, and only reports everything else.

GitHub Action

name: CRA Watch
on:
  push:
  pull_request:
  schedule:
    - cron: '0 6 * * *'   # daily: the list changes when CISA adds to it, not when you push
jobs:
  scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: abinjohnson400-beep/crawatch.dev@v2
        with:
          lockfile: package-lock.json
          fail-on: kev        # kev (default) | any | none

Outputs: kev (count on the exploited list), findings (all known vulnerabilities) and share (a link to the result page). A KEV hit also raises a workflow warning.

CLI

npx crawatch <lockfile> [--fail-on kev|any|none] [--json]

| exit | meaning | |---|---| | 0 | nothing at or above the --fail-on level | | 1 | a dependency matched the --fail-on level | | 2 | usage error, unreadable file, or the scan could not be reached |

Supported: package-lock.json, npm-shrinkwrap.json, yarn.lock (classic and berry), pnpm-lock.yaml, requirements.txt (== pins), Pipfile.lock, poetry.lock, uv.lock, Cargo.lock, go.mod, go.sum, Gemfile.lock, composer.lock, packages.lock.json, pom.xml, gradle.lockfile, pubspec.lock, mix.lock, Package.resolved, and CycloneDX or SPDX JSON.

What is sent

Package names and versions from the file, to https://crawatch.dev/api/scan, which checks them against OSV.dev and the CISA KEV catalog. Nothing else from your repository. The result is kept so the share link works. Rate limit: 30 scans an hour per IP. Privacy policy.

Free tools on the same data

The part CI does not do

A scheduled run tells you something in a CI log. It does not email you at the moment CISA lists a dependency, start the 24/72-hour/14-day clock, draft the ENISA early warning, or keep the audit trail a market-surveillance authority can ask for. CRA Watch does. The first 100 accounts pay €14 a month for life.

Licence

MIT. Not legal advice.