Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
23 changes: 23 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,29 @@

All notable changes to CVE Lite CLI will be documented in this file.

## [1.32.0] - 2026-09-01

### Added

- `--incomplete-policy warn|error` (default: `warn`): when detection data is incomplete, `warn` exits 0 with a warning; `error` exits 3. GitHub Action gains `incomplete-policy` input with empty default for backward compatibility (#1019, @luojiyin1987, closes #898)
- EPSS scores: findings are enriched with FIRST.org Exploit Prediction Scoring System data after the OSV pass. All CVE aliases are batch-fetched in a single API call. Highest-EPSS score shown in compact terminal top-3 block, verbose table column, and HTML report detail panel; full array in JSON output. Skipped in offline mode and for GHSA-only findings (#1053)
- npm advisory secondary source: after the OSV batch pass, packages with zero OSV matches are checked against the npm registry advisory API (`POST https://registry.npmjs.org/-/npm/v1/security/advisories/bulk`). Closes the coverage gap for CVEs that exist in OSV but have no npm ecosystem mapping. Skips in offline mode, non-fatal on error (#1056, closes #1054)
- `--check-licenses` flag: detect copyleft (LC001: GPL-2.0/3.0, AGPL-3.0, LGPL, EUPL, OSL, CDDL, CPL, EPL) and unknown (LC002: no declared license) licenses across the dependency tree in the same pass as the CVE scan. Informational only - never affects exit code or `--fail-on`. Surfaces in terminal, JSON, SARIF, and HTML reports. GitHub Action gains `check-licenses` input (#1059, closes #1058)

### Fixed

- Direct parent version collision: `resolveDirectParentContext` used a name-keyed Map (last-write-wins) to find the direct parent version, producing wrong `currentVersion` baselines and downgrade suggestions when the same package name is installed at multiple different versions. Fixed by using `findPackageAlongPath` with the path prefix to the direct parent position (#1051, closes #1050)

### Tests

- Add unit coverage for `src/utils/advisory.ts` (git+ssh:// protocol parsing, short-SHA alias resolution, scope handling, `parseAdvisoryOrCommand` edge cases) (#1046, @suhanemathur, closes #1024)

### Docs

- README comparison table: link each capability row to its corresponding docs page (#1064, closes #1063)
- Comparison tables and homepage updated for `--check-licenses`: new row in README and comparison.md, socket.md updated, snyk.md prose updated, homepage FeatureCard and capability pill added, workflow-integration.md gains "License compliance in CI" section (#1061, closes #1060)
- Vulnerability data source descriptions updated to reflect OSV + npm registry advisory API dual-source approach across README, how-it-works, caching, cli-reference, getting-started (#1062, closes #1057)

## [1.31.0] - 2026-08-27

### Added
Expand Down
4 changes: 2 additions & 2 deletions package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "cve-lite-cli",
"version": "1.31.0",
"version": "1.32.0",
"description": "Developer-friendly CLI for scanning JS/TS projects for dependency vulnerabilities using local lockfiles and OSV",
"type": "module",
"bin": {
Expand Down
2 changes: 1 addition & 1 deletion website/docusaurus.config.ts
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@ import {themes as prismThemes} from 'prism-react-renderer';
import type {Config} from '@docusaurus/types';
import type * as Preset from '@docusaurus/preset-classic';

const latestVersion = 'v1.31.0';
const latestVersion = 'v1.32.0';

const config: Config = {
title: 'CVE Lite CLI',
Expand Down