Arguss Observatory

Open-source ecosystem health

Dependency health of curated top npm repositories, each project's own dev and production toolchain, scanned with vulnerability, trust, and pipeline lenses.

14 projects tracked · Last refreshed Jul 21, 2026 · Powered by Arguss three-lens engine

Projects tracked
14
Curated top-npm repositories
Critical findings
73
Across all projects
KEV-flagged
2
Known exploited vulns
Auto-fix ready
113
Safe merge candidates
axios
axios/axios
283 findings 2 of 283 reach production
Crit (31)
High (152)
Med (81)
46 auto-fix 37 review
node-cross-spawn
moxystudio/node-cross-spawn
158 findings 0 of 158 reach production
Crit (9)
High (88)
Med (49)
27 auto-fix 33 review
express
expressjs/express
12 findings 0 of 12 reach production
Crit (1)
High (6)
Med (3)
4 review
node-fetch
node-fetch/node-fetch
20 findings 0 of 20 reach production
Crit (1)
High (8)
Med (9)
4 auto-fix 8 review
node-semver
npm/node-semver
17 findings 0 of 17 reach production
Crit (0)
High (9)
Med (6)
8 auto-fix 1 review
webpack
webpack/webpack
4 findings 0 of 4 reach production
Crit (0)
High (0)
Med (4)
2 auto-fix
eslint
eslint/eslint
43 findings 0 of 43 reach production
Crit (1)
High (20)
Med (20)
4 auto-fix 7 review
commander.js
tj/commander.js
1 findings 0 of 1 reach production
Crit (0)
High (0)
Med (1)
1 auto-fix
dotenv
motdotla/dotenv
128 findings 0 of 128 reach production
Crit (1)
High (69)
Med (42)
13 auto-fix 8 review
minimist
minimistjs/minimist
49 findings 0 of 49 reach production
Crit (7)
High (23)
Med (16)
16 review
chalk
chalk/chalk
40 findings 0 of 40 reach production
Crit (1)
High (13)
Med (21)
KEV 1 auto-fix 2 review
prettier
prettier/prettier
1 findings 1 of 1 reach production
Crit (0)
High (1)
Med (0)
1 review
lodash
lodash/lodash
231 findings 0 of 231 reach production
Crit (21)
High (116)
Med (88)
KEV 60 review
TypeScript
microsoft/TypeScript
14 findings 0 of 14 reach production
Crit (0)
High (2)
Med (11)
7 auto-fix 1 review

Research & whitepaper use

Observatory data powers the Arguss capstone research. Historical scans reveal which packages appear most often as vulnerable transitive dependencies, which maintainers have the best trust scores, and what percentage of critical CVEs have auto-fix candidates, across the most important npm projects on the internet.

About the project →