Arguss Observatory
Open-source ecosystem health
Dependency health of curated top npm repositories, each project's own dev and production toolchain, scanned with vulnerability, trust, and pipeline lenses.
Projects tracked
14
Curated top-npm repositories
Critical findings
71
Across all projects
KEV-flagged
2
Known exploited vulns
Auto-fix ready
97
Safe merge candidates
axios
axios/axios
307 findings
2 of 307 reach production
43 auto-fix
40 review
node-cross-spawn
moxystudio/node-cross-spawn
163 findings
0 of 163 reach production
26 auto-fix
34 review
express
expressjs/express
4 findings
0 of 4 reach production
3 review
node-fetch
node-fetch/node-fetch
20 findings
0 of 20 reach production
4 auto-fix
8 review
node-semver
npm/node-semver
19 findings
0 of 19 reach production
7 auto-fix
2 review
webpack
webpack/webpack
21 findings
0 of 21 reach production
2 auto-fix
2 review
eslint
eslint/eslint
45 findings
0 of 45 reach production
5 auto-fix
7 review
commander.js
tj/commander.js
3 findings
0 of 3 reach production
1 auto-fix
dotenv
motdotla/dotenv
32 findings
0 of 32 reach production
3 auto-fix
2 review
minimist
minimistjs/minimist
51 findings
0 of 51 reach production
16 review
chalk
chalk/chalk
49 findings
0 of 49 reach production
KEV
1 review
prettier
prettier/prettier
1 findings
1 of 1 reach production
1 review
lodash
lodash/lodash
236 findings
0 of 236 reach production
KEV
60 review
TypeScript
microsoft/TypeScript
20 findings
0 of 20 reach production
6 auto-fix
2 review
Research & whitepaper use
Observatory data powers the Arguss capstone research. Historical scans reveal which packages appear most often as vulnerable transitive dependencies, which maintainers have the best trust scores, and what percentage of critical CVEs have auto-fix candidates, across the most important npm projects on the internet.