| Version | Support status |
|---|---|
| 2.x (latest) | ✅ Active — security fixes applied |
| 1.x | ❌ End of life — upgrade to v2 |
Do not open a public GitHub issue for suspected vulnerabilities.
Use GitHub's private vulnerability reporting feature:
👉 https://github.com/om-tajne/pkgdiet/security/advisories/new
Please include:
- Affected package and version
- Reproduction steps
- Impact assessment
- Proof of concept (if safe to share)
- Suggested mitigation, if known
We aim to acknowledge reports within 48 hours. This is a target, not a guarantee.
PkgDiet sends package names only to public npm registry endpoints (registry.npmjs.org, api.npmjs.org) when network checks are enabled. It also queries the OSV.dev public advisory API (api.osv.dev/v1/query) with the package name and resolved version to check for known vulnerabilities. No source code, file contents, project structure, or private data is ever transmitted. All other data (cache, metrics, policy) stays on the local machine.
To disable all network requests: PKGDIET_NO_NETWORK=1 npx pkgdiet check <pkg>
To disable only vulnerability advisory lookups: PKGDIET_ADVISORIES=0 npx pkgdiet check <pkg>
The supported security surface is the npm-published packages:
pkgdiet(CLI)@pkgdiet/core@pkgdiet/mcp
The GitHub App and dashboard (apps/) are experimental and not part of the supported release.