Skip to main content

Case Studies

Each study is a real scan of a popular open source project - baseline findings recorded, fix commands run, results rescanned and measured. No estimated numbers.

These studies demonstrate CVE Lite CLI across different package managers, lockfile shapes, and project types: monorepos, transitive-heavy graphs, projects with no direct findings, and projects where the most interesting vulnerability is one npm audit would omit.

CVE Lite CLI is an OWASP Lab Project.


ProjectLockfileKey finding
CamoFox BrowsernpmAI agent browser automation — 435 packages, 2 qs findings, within-range refresh + express parent upgrade
GhostnpmCMS platform, transitive chain analysis
lint-stagednpm[email protected] direct high dep hidden by npm audit --omit=dev
LitnpmWeb components reference implementation — 2,059 packages, 3 direct rollup findings with workspace-scoped fix commands, 5 critical transitive
NestJSnpm26 findings, 25 transitive - CVE Lite surfaces the one actionable direct fix
OWASP Juice ShopnpmMultiple critical/high direct findings with copy-and-run fix commands
Payload CMSpnpmTypeScript-first headless CMS — 2,602 packages, 1 direct finding, workspace-scoped remediation
Presentonnpm (dual lockfile)AI presentation generator — dual npm lockfiles (root + Electron), 9 findings, 5 fix groups
StorybooknpmFrontend tooling, large dependency graph
StrapiYarn BerryHeadless CMS monorepo — 2,887 packages, 2 direct findings (lodash, qs), 15 transitive
VS Codenpm@anthropic-ai/[email protected]/0.82 as direct Copilot dependencies
AnalogpnpmAngular meta-framework monorepo, pnpm workspace scanning
AstropnpmLarge pnpm monorepo with verified baseline scan documentation
LangChain.jspnpmLLM application framework monorepo — 2,174 packages, lean graph, 3 high with validated targets, malicious-package advisory on OpenSearch integration paths
MastrapnpmAI agent framework — 4,555 packages, 4 direct findings, workspace-scoped pnpm add
n8npnpmWorkflow automation monorepo — 3,746 packages, 1 direct turbo fix, 4 command groups, 31 transitive
OpenAI Agents SDK (JS)pnpmAI agent monorepo — 1,683 packages, 0 direct findings, 31 transitive, one verdaccio parent-upgrade command
TurborepopnpmMonorepo build tooling, pnpm lockfile
Vercel AI SDKpnpmAI SDK monorepo — 3 direct findings, 5 workspace-scoped fix command groups
GatsbyYarn ClassicLarge Yarn v1 monorepo — 3,568 packages, 128 findings, 5 direct
TwentyYarn BerryOpen-source CRM — 5,451 packages, 105 findings, 0 direct, Nx orchestration layer