Arguss Observatory
Open-source ecosystem health
Dependency health of curated top npm repositories, each project's own dev and production toolchain, scanned with vulnerability, trust, and pipeline lenses.
Projects tracked
14
Curated top-npm repositories
Critical findings
73
Across all projects
KEV-flagged
2
Known exploited vulns
Auto-fix ready
113
Safe merge candidates
axios
axios/axios
283 findings
2 of 283 reach production
46 auto-fix
37 review
node-cross-spawn
moxystudio/node-cross-spawn
158 findings
0 of 158 reach production
27 auto-fix
33 review
express
expressjs/express
12 findings
0 of 12 reach production
4 review
node-fetch
node-fetch/node-fetch
20 findings
0 of 20 reach production
4 auto-fix
8 review
node-semver
npm/node-semver
17 findings
0 of 17 reach production
8 auto-fix
1 review
webpack
webpack/webpack
4 findings
0 of 4 reach production
2 auto-fix
eslint
eslint/eslint
43 findings
0 of 43 reach production
4 auto-fix
7 review
commander.js
tj/commander.js
1 findings
0 of 1 reach production
1 auto-fix
dotenv
motdotla/dotenv
128 findings
0 of 128 reach production
13 auto-fix
8 review
minimist
minimistjs/minimist
49 findings
0 of 49 reach production
16 review
chalk
chalk/chalk
40 findings
0 of 40 reach production
KEV
1 auto-fix
2 review
prettier
prettier/prettier
1 findings
1 of 1 reach production
1 review
lodash
lodash/lodash
231 findings
0 of 231 reach production
KEV
60 review
TypeScript
microsoft/TypeScript
14 findings
0 of 14 reach production
7 auto-fix
1 review
Research & whitepaper use
Observatory data powers the Arguss capstone research. Historical scans reveal which packages appear most often as vulnerable transitive dependencies, which maintainers have the best trust scores, and what percentage of critical CVEs have auto-fix candidates, across the most important npm projects on the internet.