audit
Scan your dependencies for known vulnerabilities.
Checks your project's dependencies against the OSV.dev vulnerability database — npm, crates.io, Go, PyPI and Packagist — and tells you what to fix. Findings are ranked by whether they can actually hurt you: production dependencies keep full severity, dev-only tools are downgraded, and deep transitive noise is grouped so the report stays readable. One repo, or every repo you have.