Find and fix vulnerable npm dependencies


This software composition analysis (SCA) tool detects and upgrades dependencies with publicly disclosed vulnerabilities. This recipe both generates a report of vulnerable dependencies and upgrades to newer versions with fixes. This recipe only upgrades to the latest patch version. If a minor or major upgrade is required to reach the fixed version, this recipe will not make any changes. Vulnerability information comes from the GitHub Security Advisory Database, which aggregates vulnerability data from several public databases, including the National Vulnerability Database maintained by the United States government. Dependencies following Semantic Versioning will see their patch version updated where applicable.

Recipe source

GitHub, Issue Tracker, Maven Central

  • groupId: org.openrewrite.recipe

  • artifactId: rewrite-nodejs

  • version: 0.8.0





Optional. Report each vulnerability as search result markers. When enabled you can see which dependencies are bringing in vulnerable transitives in the diff view. By default these markers are omitted, making it easier to see version upgrades within the diff.


This recipe has no required configuration options. It can be activated by adding a dependency on org.openrewrite.recipe:rewrite-nodejs:0.8.0 in your build file or by running a shell command (in which case no build changes are needed):

  1. Add the following to your build.gradle file:

plugins {
    id("org.openrewrite.rewrite") version("6.23.3")

rewrite {
    exportDatatables = true

repositories {

dependencies {
  1. Run gradle rewriteRun to run the recipe.

See how this recipe works across multiple open-source repositories

The community edition of the Moderne platform enables you to easily run recipes across thousands of open-source repositories.

Please contact Moderne for more information about safely running the recipes on your own codebase in a private SaaS.

Data Tables

Vulnerability report


A vulnerability report that includes detailed information about the affected artifact and the corresponding CVEs.

Column NameDescription


The CVE number.

Package name

The package name.


The resolved version.

Fixed in version

The minimum version that is no longer vulnerable.

Fixable with version update only

Whether the vulnerability is likely to be fixed by increasing the dependency version only, with no code modifications required. This is a heuristic which assumes that the dependency is accurately versioned according to semver.


The summary of the CVE.

Base score

The calculated base score.


Zero for direct dependencies.


Common Weakness Enumeration (CWE) identifiers; semicolon separated.

Source files that had results


Source files that were modified by the recipe run.

Column NameDescription

Source path before the run

The source path of the file before the run. null when a source file was created during the run.

Source path after the run

A recipe may modify the source path. This is the path after the run. null when a source file was deleted during the run.

Parent of the recipe that made changes

In a hierarchical recipe, the parent of the recipe that made a change. Empty if this is the root of a hierarchy or if the recipe is not hierarchical at all.

Recipe that made changes

The specific recipe that made a change.

Estimated time saving

An estimated effort that a developer to fix manually instead of using this recipe, in unit of seconds.


The recipe cycle in which the change was made.

Source files that errored on a recipe


The details of all errors produced by a recipe run.

Column NameDescription

Source path

The file that failed to parse.

Recipe that made changes

The specific recipe that made a change.

Stack trace

The stack trace of the failure.

Recipe performance


Statistics used in analyzing the performance of recipes.

Column NameDescription

The recipe

The recipe whose stats are being measured both individually and cumulatively.

Source file count

The number of source files the recipe ran over.

Source file changed count

The number of source files which were changed in the recipe run. Includes files created, deleted, and edited.

Cumulative scanning time

The total time spent across the scanning phase of this recipe.

99th percentile scanning time

99 out of 100 scans completed in this amount of time.

Max scanning time

The max time scanning any one source file.

Cumulative edit time

The total time spent across the editing phase of this recipe.

99th percentile edit time

99 out of 100 edits completed in this amount of time.

Max edit time

The max time editing any one source file.

Last updated