dev
npm known exploited vulnerabilities
npm is in the path of source, CI, or packages. Exploited-class bugs here are supply-chain events for anyone who ships software. In this catalog npm depends on GitHub (parent company). Keep Track fans KEV hits on those names out as supplier matches.
Suppliers behind npm
- GitHub — parent
Matched KEV and critical CVEs
No catalog matches stored for npm yet. Ingest runs from CISA KEV every six hours. See the live tracker.
Add npm to your watchlist.
Three tools free. Keep Track is $20/month for supplier blast-radius, full history, and a digest.