Skip to content

Repository files navigation

siro

CI npm license

A security-configuration linter for npm, pnpm, Yarn, Bun, Deno, and Aube. It reports supported dependency-installation and publication policy gaps, such as permissive lifecycle scripts, unpinned versions, and missing publication safeguards. It does not install packages or change your files.

Approach Primary question Typical input
siro: configuration lint Are supported install/publish settings risky? Repository manifests and configuration files
Dependency vulnerability scan Do dependencies match known advisories? Dependency inventory and vulnerability data
Dependency update automation Which dependencies can be updated? Manifests, lockfiles, and package registries

These approaches complement one another; a clean result does not guarantee safety.

Try it

Requires Node.js ^22.18.0 or ^24.0.0. From your repository:

npx @pho9ubenaa/siro lint

siro recursively discovers package.json and strict deno.json below cwd, independently of PM workspace declarations. It checks local installation policy at cwd by default; add independent projects with --installation-root. Exclude intentional fixtures with --exclude test/fixtures. Discovery does not imply that every package's installation settings were inspected.

siro detects managers from packageManager, lockfiles, and configuration files. If it cannot detect one, choose it explicitly, for example npx @pho9ubenaa/siro lint --pm npm. The CLI automatically reads siro.config.json as data. npx may download code. Executable repository configuration requires an explicit --config <path> and runs with your permissions. For unfamiliar projects, --no-config --strict-filesystem narrows the inputs; neither flag is a sandbox. See the threat model.

Read findings and add CI

Findings have error, warn, or info severity. Exit 0 means no findings at or above the selected threshold; exit 1 means there are findings. Errors fail CI by default; see exit codes for 2 and 70. siro suggests fixes but does not edit files: review changes and rerun the linter.

For regular use, install it with npm install --save-dev --save-exact @pho9ubenaa/siro and add a package script:

{
  "scripts": { "lint:security": "siro lint" }
}

After installing dependencies in CI, run npm run lint:security. A local install makes siro available to package scripts, not to every shell or Git hook. For exclusions and rule overrides, see the configuration examples.

Common CLI options

check is an alias for lint. Run npx @pho9ubenaa/siro lint --help for the complete CLI syntax.

Option Use
--pm <npm|pnpm|yarn|bun|deno|aube> Select one manager at cwd; additional installation roots retain their own targets.
--pm-version <x.y.z> Supply an exact stable target version (requires --pm); it does not run an installed PM.
--project-type <application|package> Choose whether publication safeguards apply; omitted means infer from publish metadata.
--config <path> Select JSON settings or explicitly execute trusted JS/TS configuration.
--exclude <pattern> Prune directories from recursive discovery (repeatable).
--installation-root <path> Replace the default cwd installation scope (repeatable; include . to retain cwd).
--severity <error|warn|info> Set both the display and CI failure threshold; default failure threshold is error.
--reporter <pretty|json|github> Choose terminal, JSON, or GitHub Actions output; --json is a JSON shortcut.

--no-config skips repository configuration; --strict-filesystem rejects symlink input paths in native data reads. Scans also have finite caller-controlled file, tree, nesting, finding and output budgets. Overflow fails the check rather than silently skipping inputs.

Documentation by task:

If you want to… Read
Run a first scan, then add it to CI Getting started
Set options, inspection scope, config or migrate Configuration
Check what a rule does, on which inputs, at what severity Rule reference
See which package managers a rule covers PM comparison
Consume or emit the machine-readable report JSON output
Judge why a finding is justified Policy and sources
Know what a clean result does and does not prove Threat model
Build, verify or release siro Contributing

License

MIT

About

Security best-practices linter for the npm ecosystem — npm, pnpm, yarn, bun, deno, aube.

Topics

Resources

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Used by

Contributors

Languages