vulnfix is a CLI that recursively scans a project tree and applies
ecosystem-specific vulnerability fixes:
- For each directory containing
go.mod, it runs iterative Go remediation usinggovulncheckand GitHub Dependabot alerts. - For each directory containing
package.json, it runsnpm audit fix.
- Recursively finds all directories containing
go.modandpackage.json. - For each Go module directory:
Runs
govulncheck -json ./..., fetches open Dependabot Go alerts, appliesgo getupgrades, then runsgo mod tidyandgo mod vendor. - For each npm package directory:
Runs
npm audit fix. - Honors
--goand--npmtoggles to enable or disable ecosystems.
- Go toolchain with
govulncheckinstalled (go install golang.org/x/vuln/cmd/govulncheck@latest) when--go=true - Node.js and npm when
--npm=true - A GitHub personal access token (or fine-grained token) with read access to Dependabot alerts (
security_eventsscope for classic tokens) when--go=true
go install github.com/appscodelabs/vulnfix@latestvulnfix [flags]
Flags:
--dir string Root directory to recursively scan for go.mod and package.json (default: current directory)
--go Enable Go vulnerability remediation (default: true)
--npm Enable npm remediation via npm audit fix (default: true)
--repo string GitHub repository in owner/repo form
(defaults to GITHUB_REPOSITORY env var or the origin remote)
--github-token string GitHub token for Dependabot alerts
(defaults to GITHUB_TOKEN, then GH_TOOLS_TOKEN)
--pattern strings Package patterns passed to govulncheck (default: [./...])
--max-iterations int Maximum remediation passes to attempt (default: 10)
--dry-run Print planned upgrades without modifying go.mod
Fix Go and npm vulnerabilities under the current tree:
export GITHUB_TOKEN=ghp_...
vulnfixTarget a specific module directory and repository:
vulnfix --dir ./myservice --repo myorg/myservice --github-token ghp_...Run only npm fixes:
vulnfix --go=false --npm=trueRun only Go fixes:
vulnfix --go=true --npm=falsePreview the planned upgrades without making any changes:
vulnfix --dry-runThe --repo flag is resolved in the following order:
--repoflag valueGITHUB_REPOSITORYenvironment variableoriginremote URL parsed as a GitHub HTTPS or SSH URL- Any other
git remoteURL that points to GitHub
The --github-token flag is resolved in the following order:
--github-tokenflag valueGITHUB_TOKENenvironment variableGH_TOOLS_TOKENenvironment variable