Nest - modern, fast, powerful node.js web framework (@cli)
90%
Total Score
healthy
Healthy: frequent releases and active organization-backed maintenance support dependable adoption.
No build attestation or trusted-publisher provenance is present, leaving publication origin less independently verifiable despite the project's active source repository.
The repository uses established build and test tooling, including TypeScript, Vitest, Webpack, Vite, and SWC, though no security scanning tool was detected.
The repository has no published security policy, which makes vulnerability reporting and response expectations less transparent.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-180615 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @nestjs/cli is vulnerable to Path Traversal in versions 7.0.0 - 11.0.21. | 7.0.0 - 11.0.21 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
ora Version 9.4.1 | — | — |
ansis Version 4.4.0 | — | — |
chokidar Version 5.0.0 | — | — |
commander Version 15.0.0 | — | — |
minimatch Version 10.2.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.