security-audit

Use when checking for dependency vulnerabilities, accidentally committed secrets, or security issues in Docker images.

Security Audit

Purpose

Comprehensive security audit covering dependency vulnerabilities, secrets in code/git history, and container image scanning. Produces a prioritized remediation report.

Input: None (scans current project) Output: Severity-grouped vulnerability report with remediation steps

When to Use

  • Before a release
  • After adding new dependencies
  • Periodic security review

Steps

Step 1 — Dependency vulnerabilities

Auto-detect: bun.lockbbun audit | package-lock.jsonnpm audit --json | yarn.lockyarn audit

Group by severity: critical → high → moderate → low

Step 2 — Outdated packages

Run bun outdated or npm outdated. Flag packages more than 2 major versions behind.

Step 3 — Secrets scan

  • Check git history for .env, .key, .pem files
  • Grep source for hardcoded passwords/API keys/secrets (excluding node_modules)

Step 4 — Docker image scan

If Dockerfile present and Docker available: docker scout cves

Report

  • Total by severity
  • Top 3 critical/high with CVE
  • Recommended immediate actions
  • Packages safe to ignore (dev-only, not reachable in prod)

Rules

  • Distinguish prod vs dev-only vulnerabilities
  • Never suggest npm audit fix --force without explaining what it changes