npm-scan
Version updated for https://github.com/lateos-ai/npm-scan to version v1.5.1.
- This action is used across all versions by 0 repositories.
Action Type
This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary
Purpose and Functionality: npm-scan is an advanced tool designed to detect a wide range of supply chain attacks, including eBPF kernel rootkits, memory extraction, credential theft, GitHub spoofing, AI-targeted attacks, and more. It complements traditional tools like npm audit and Snyk by offering behavioral detection that can identify hidden threats.
Problems Solved or Tasks Automated: By detecting known vulnerabilities as well as advanced attack vectors, npm-scan helps organizations reduce their risk of data breaches, regulatory fines, downtime, and reputational damage. It provides a comprehensive approach to supply chain security that ensures businesses are protected against emerging threats.
Key Capabilities: The action is capable of scanning individual packages or the entire node package ecosystem, exporting findings to JSON format for easier analysis, and detecting 23 types of attacks with high confidence rates.