Last active
October 22, 2015 22:56
-
-
Save rjz/6c9ad04f884c1911790d to your computer and use it in GitHub Desktop.
Scan node package dependencies for vulnerabilities
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
#!/bin/sh | |
# Check for vulnerabilities in package dependencies | |
# | |
# Script extracted from https://github.com/rjz/node-boilerplate | |
# | |
# Reference: http://blog.nodesecurity.io/2014/02/01/new-feature-validate-modules-with-npm-shrinkwrap | |
if [ ! -f 'npm-shrinkwrap.json' ]; then | |
echo 'Audit [FAIL]: Create npm-shrinkwrap.json by running: | |
$ npm shrinkwrap | |
' | |
exit 1; | |
fi | |
VULNERABILITIES=$(curl -s -XPOST \ | |
-d@npm-shrinkwrap.json \ | |
-HContent-type:application/json \ | |
https://nodesecurity.io/validate/shrinkwrap) | |
size=${#VULNERABILITIES} | |
if [ "$size" -eq "2" ]; then | |
echo 'Audit [PASS]: no vulnerabilities found in listed dependencies!' | |
exit 0; | |
else | |
echo 'Audit [FAIL]: vulnerabilities discovered in shrinkwrapped dependencies!' | |
echo "$VULNERABILITIES" | |
exit 1; | |
fi |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment