Arguss Observatory

Open-source ecosystem health

Dependency health of curated top npm repositories, each project's own dev and production toolchain, scanned with vulnerability, trust, and pipeline lenses.

14 projects tracked · Last refreshed Aug 05, 2026 · Powered by Arguss three-lens engine

Projects tracked
14
Curated top-npm repositories
Critical findings
71
Across all projects
KEV-flagged
2
Known exploited vulns
Auto-fix ready
97
Safe merge candidates
axios
axios/axios
307 findings 2 of 307 reach production
Crit (31)
High (170)
Med (87)
43 auto-fix 40 review
node-cross-spawn
moxystudio/node-cross-spawn
163 findings 0 of 163 reach production
Crit (9)
High (92)
Med (50)
26 auto-fix 34 review
express
expressjs/express
4 findings 0 of 4 reach production
Crit (0)
High (2)
Med (1)
3 review
node-fetch
node-fetch/node-fetch
20 findings 0 of 20 reach production
Crit (1)
High (8)
Med (9)
4 auto-fix 8 review
node-semver
npm/node-semver
19 findings 0 of 19 reach production
Crit (0)
High (11)
Med (6)
7 auto-fix 2 review
webpack
webpack/webpack
21 findings 0 of 21 reach production
Crit (0)
High (16)
Med (5)
2 auto-fix 2 review
eslint
eslint/eslint
45 findings 0 of 45 reach production
Crit (1)
High (20)
Med (22)
5 auto-fix 7 review
commander.js
tj/commander.js
3 findings 0 of 3 reach production
Crit (0)
High (2)
Med (1)
1 auto-fix
dotenv
motdotla/dotenv
32 findings 0 of 32 reach production
Crit (0)
High (27)
Med (5)
3 auto-fix 2 review
minimist
minimistjs/minimist
51 findings 0 of 51 reach production
Crit (7)
High (25)
Med (16)
16 review
chalk
chalk/chalk
49 findings 0 of 49 reach production
Crit (1)
High (13)
Med (28)
KEV 1 review
prettier
prettier/prettier
1 findings 1 of 1 reach production
Crit (0)
High (1)
Med (0)
1 review
lodash
lodash/lodash
236 findings 0 of 236 reach production
Crit (21)
High (120)
Med (89)
KEV 60 review
TypeScript
microsoft/TypeScript
20 findings 0 of 20 reach production
Crit (0)
High (8)
Med (11)
6 auto-fix 2 review

Research & whitepaper use

Observatory data powers the Arguss capstone research. Historical scans reveal which packages appear most often as vulnerable transitive dependencies, which maintainers have the best trust scores, and what percentage of critical CVEs have auto-fix candidates, across the most important npm projects on the internet.

About the project →