npm CVE Scanning in CircleCI CircleCI

Add npm vulnerability scanning to your CircleCI pipeline. Catch dependency CVEs on every build.

npm audit in CircleCI

Use OSV Scanner in CircleCI to flag CVEs on every push.

version: 2.1
jobs:
  security-scan:
    docker:
      - image: cimg/node:18.0
    steps:
      - checkout
      - run:
          name: Install OSV Scanner
          command: go install github.com/google/osv-scanner/cmd/osv-scanner@latest
      - run:
          name: Scan dependencies
          command: osv-scanner --lockfile=package-lock.json
✓ Manual Scan

For a quick one-off scan before deployment, paste your package.json into PackageFix — no pipeline setup needed.

Scan your dependencies now — paste your manifest, get a fixed version back in seconds.

Open PackageFix →

No signup · No CLI · No GitHub connection · Runs 100% in your browser

Frequently Asked Questions

How do I add dependency scanning to CircleCI?
Add OSV Scanner or the ecosystem-specific audit tool to your CircleCI build configuration. The config snippet above works out of the box.
Does PackageFix integrate with CI/CD pipelines?
PackageFix is a browser tool for manual scans. For automated CI scanning, use OSV Scanner (Google) or pip-audit/npm audit in your pipeline. PackageFix generates the Renovate config and GitHub Actions workflow you can copy.
How do I fail a CircleCI build on critical CVEs?
Add --audit-level=critical to npm audit, or --fail-on=critical to pip-audit. The pipeline aborts if critical CVEs are found.
What is the OSV Scanner?
OSV Scanner is Google's open-source CLI tool that queries the same OSV database PackageFix uses. It's ideal for CI/CD integration.