The batteries-included, No-Code FinOps automation platform, with the AI you trust.
# Add to your Claude Code skills
git clone https://github.com/openops-cloud/openopsLast scanned: 5/2/2026
{
"issues": [
{
"type": "npm-audit",
"message": "@aws-sdk/xml-builder: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@azure/identity: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@azure/msal-node: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@babel/runtime: Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@chevrotain/cst-dts-gen: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@chevrotain/gast: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@fastify/static: @fastify/static vulnerable to path traversal in directory listing",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@fastify/swagger-ui: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@frontegg/js: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@frontegg/redux-store: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@frontegg/types: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@google-cloud/storage: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@mapbox/node-pre-gyp: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@mermaid-js/parser: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@microsoft/api-extractor: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@modelcontextprotocol/sdk: @modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@module-federation/dts-plugin: Vulnerability found",
"severity": "low"
},
{
"type": "npm-audit",
"message": "@module-federation/enhanced: Vulnerability found",
"severity": "low"
},
{
"type": "npm-audit",
"message": "@module-federation/manifest: Vulnerability found",
"severity": "low"
},
{
"type": "npm-audit",
"message": "@module-federation/rspack: Vulnerability found",
"severity": "low"
},
{
"type": "npm-audit",
"message": "@npmcli/arborist: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@npmcli/metavuln-calculator: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@npmcli/run-script: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@nrwl/devkit: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@nrwl/esbuild: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@nrwl/eslint-plugin-nx: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@nrwl/jest: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@nrwl/js: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@nrwl/node: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@nrwl/nx-cloud: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@nrwl/tao: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@nrwl/vite: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@nrwl/web: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@nrwl/workspace: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@nx/cypress: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@nx/devkit: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@nx/esbuild: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@nx/eslint: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@nx/eslint-plugin: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@nx/jest: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@nx/js: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@nx/linter: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@nx/module-federation: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@nx/node: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@nx/react: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@nx/storybook: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@nx/vite: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@nx/web: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@nx/webpack: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@nx/workspace: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@sigstore/sign: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@sigstore/tuf: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@storybook/addon-actions: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@storybook/addon-essentials: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@storybook/test-runner: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@swc/cli: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@tootallnate/once: @tootallnate/once vulnerable to Incorrect Control Flow Scoping",
"severity": "low"
},
{
"type": "npm-audit",
"message": "@xhmikosr/archive-type: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@xhmikosr/bin-wrapper: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@xhmikosr/decompress: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@xhmikosr/decompress-tar: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@xhmikosr/decompress-tarbz2: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@xhmikosr/decompress-targz: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@xhmikosr/decompress-unzip: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@xhmikosr/downloader: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "aws-lambda: Vulnerability found",
"severity": "low"
},
{
"type": "npm-audit",
"message": "aws-sdk: JavaScript SDK v2 users should add validation to the region parameter value in or migrate to v3",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "bcrypt: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "brace-expansion: brace-expansion Regular Expression Denial of Service vulnerability",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "bullmq: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "cacache: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "chevrotain: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "cookie: cookie accepts cookie name, path, and domain with out of bounds characters",
"severity": "low"
},
{
"type": "npm-audit",
"message": "copy-webpack-plugin: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "cross-spawn: Regular Expression Denial of Service (ReDoS) in cross-spawn",
"severity": "high"
},
{
"type": "npm-audit",
"message": "css-minimizer-webpack-plugin: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "diff: jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch",
"severity": "low"
},
{
"type": "npm-audit",
"message": "dompurify: DOMPurify's ADD_TAGS function form bypasses FORBID_TAGS due to short-circuit evaluation",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "engine.io: Vulnerability found",
"severity": "low"
},
{
"type": "npm-audit",
"message": "esbuild: esbuild enables any website to send any requests to the development server and read the response",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "external-editor: Vulnerability found",
"severity": "low"
},
{
"type": "npm-audit",
"message": "fast-xml-parser: fast-xml-parser affected by numeric entity expansion bypassing all entity expansion limits (incomplete fix for CVE-2026-26278)",
"severity": "high"
},
{
"type": "npm-audit",
"message": "fastify: Fastify has a Body Schema Validation Bypass via Leading Space in Content-Type Header",
"severity": "high"
},
{
"type": "npm-audit",
"message": "file-type: file-type affected by infinite loop in ASF parser on malformed input with zero-size sub-header",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "follow-redirects: follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect Targets",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "gaxios: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "glob: glob CLI: Command injection via -c/--cmd executes matches with shell:true",
"severity": "high"
},
{
"type": "npm-audit",
"message": "http-proxy-agent: Vulnerability found",
"severity": "low"
},
{
"type": "npm-audit",
"message": "i18next-http-backend: i18next-http-backend has Path Traversal & URL Injection via Unsanitised lng/ns",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "i18next-parser: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "imapflow: Vulnerability found",
"severity": "low"
},
{
"type": "npm-audit",
"message": "inquirer: Vulnerability found",
"severity": "low"
},
{
"type": "npm-audit",
"message": "istanbul-lib-processinfo: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "jest-environment-jsdom: Vulnerability found",
"severity": "low"
},
{
"type": "npm-audit",
"message": "jest-junit: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "jest-playwright-preset: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "js-yaml: js-yaml has prototype pollution in merge (<<)",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "jsdom: Vulnerability found",
"severity": "low"
},
{
"type": "npm-audit",
"message": "jshint: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "koa: Koa Open Redirect via Referrer Header (User-Controlled)",
"severity": "high"
},
{
"type": "npm-audit",
"message": "langium: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "libnpmaccess: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "libnpmdiff: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "libnpmexec: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "libnpmfund: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "libnpmhook: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "libnpmorg: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "libnpmpack: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "libnpmpublish: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "libnpmsearch: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "libnpmteam: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "libnpmversion: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "lint-staged: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "lodash: lodash vulnerable to Code Injection via `_.template` imports key names",
"severity": "high"
},
{
"type": "npm-audit",
"message": "lodash-es: Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions",
"severity": "high"
},
{
"type": "npm-audit",
"message": "mailparser: Vulnerability found",
"severity": "low"
},
{
"type": "npm-audit",
"message": "make-fetch-happen: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "mermaid: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "minimatch: minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern",
"severity": "high"
},
{
"type": "npm-audit",
"message": "node-cron: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "node-gyp: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "nodemailer: Nodemailer has SMTP command injection due to unsanitized `envelope.size` parameter",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "npm: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "npm-profile: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "npm-registry-fetch: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "nx: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "nx-cloud: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "nyc: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "pacote: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "picomatch: Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching",
"severity": "high"
},
{
"type": "npm-audit",
"message": "postcss: PostCSS has XSS via Unescaped </style> in its CSS Stringify Output",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "postcss-url: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "prismjs: PrismJS DOM Clobbering vulnerability",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "react-router: React Router has CSRF issue in Action/Server Action Request Processing",
"severity": "high"
},
{
"type": "npm-audit",
"message": "react-router-dom: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "react-syntax-highlighter: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "refractor: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "retry-request: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "serialize-javascript: Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()",
"severity": "high"
},
{
"type": "npm-audit",
"message": "showdown: Showdown vulnerable to Regular Expression Denial of Service (ReDoS) in link/anchor parsing",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "sigstore: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "snowflake-sdk: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "socket.io: Vulnerability found",
"severity": "low"
},
{
"type": "npm-audit",
"message": "sockjs: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "sqlite3: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "tar: node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal",
"severity": "high"
},
{
"type": "npm-audit",
"message": "teeny-request: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "tmp: tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter",
"severity": "low"
},
{
"type": "npm-audit",
"message": "tuf-js: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "typeorm: TypeORM vulnerable to SQL injection via crafted request to repository.save or repository.update",
"severity": "high"
},
{
"type": "npm-audit",
"message": "uuid: uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "validator: validator.js has a URL validation bypass vulnerability in its isURL function",
"severity": "high"
},
{
"type": "npm-audit",
"message": "vite: Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "webpack-dev-server: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "yaml: yaml is vulnerable to Stack Overflow via deeply nested YAML collections",
"severity": "medium"
}
],
"status": "WARNING",
"scannedAt": "2026-05-02T06:10:27.152Z",
"semgrepRan": false,
"npmAuditRan": true,
"pipAuditRan": true
}No comments yet. Be the first to share your thoughts!

OpenOps is a No-Code FinOps automation platform that helps organizations reduce cloud costs and streamline financial operations.
It provides customizable workflows to automate key FinOps processes like allocation, unit economics, anomaly management, workload optimization, safe de-provisioning and much, much more.
It also comes bundled with its own Excel-like database (OpenOps Tables) and its own visualization system (OpenOps Analytics).
At the same time, OpenOps enables collaboration between FinOps teams, engineers, DevOps, finance, and leadership, ensuring that cost-saving measures are not just identified but effectively implemented.
OpenOps integrates seamlessly with major cloud providers, many third-party FinOps tools, various communication platforms and a handful of project management tools.
🏁 Just want to get started? Click here.

FinOps practitioners struggle with visibility tools that surface cost-saving opportunities but lack implementation capabilities. Traditional automation tools, whether custom-built or off-the-shelf, fail to balance flexibility and maintainability.
OpenOps solves these challenges by:
With OpenOps, organizations can automate cloud cost optimization, ensuring that FinOps processes are efficient, actionable, and aligned with business goals.
OpenOps integrates with a broad range of platforms, including cloud providers, databases, FinOps tools, communication platforms, and task management services.
OpenOps is available as:
docker-compose-based installation (can be installed locally or in the cloud)For detailed documentation, visit our documentation portal.
We welcome contributions to OpenOps! See our contributing guide for details.
OpenOps is licensed under the Apache License 2.0.
OpenOps has a Slack community - feel free to join here.