Scans the installed dependency tree against the npm advisory database and lists vulnerabilities with severity and fix versions. Run it in CI to fail on high-severity issues. Yarn classic checks the lockfile, so keep it committed.
Looking for more? Search all 7,657 commands — works offline, in English or Spanish, and fixes typos.