Hierarchical node.js configuration with files, environment variables, command-line arguments, and atomic object merging.
79%
Total Score
44
100
100
100
50
| Title | Versions | Severity |
|---|---|---|
CVE-2022-21803 nconf is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in versions 0.0.0 - 0.11.4. | 0.0.0 - 0.11.4 | High |
| Dependency | Last Release | Score |
|---|---|---|
ini Version ^2.0.0 | — | — |
async Version ^3.0.0 | — | — |
yargs Version ^16.1.1 | — | — |
secure-keys Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant