Ross ROSS = Recommend OSS · open-source software intelligence for agents

lunasec-io/lunasec

LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and Builds. Protect yourself in 30 seconds with the LunaTrace GitHub App: https://github.com/marketplace/lunatrace-by-lunasec/ observed · 2026-08-28

github.com/lunasec-io/lunasec · homepage · TypeScript · NOASSERTION (other) observed · 2026-08-28

Health v2 · maintenance only

23/100

  • Activity 0
  • Release rhythm 8
  • Longevity 100

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 1996
  • days_rel: n/a
  • days_push: 853
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1469 stars · 167 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

LunaSec is an open-source supply chain security suite whose main product, LunaTrace, scans project dependencies for vulnerabilities like Log4Shell and reports them in GitHub pull requests and builds. The monorepo also includes a Log4Shell scanning/patching CLI and LunaDefend, a tokenization-based data protection suite.

Use cases

  • scan dependencies for CVEs in pull requests
  • generate SBOMs for my projects
  • find and patch Log4Shell in jars
  • self-hosted alternative to Snyk or Dependabot
  • monitor npm packages for vulnerabilities like node-ipc
  • tokenize sensitive data to meet PCI and SOC2 compliance

When to choose

  • you want automated dependency vulnerability alerts integrated with GitHub PRs
  • you need an open-source, self-hostable SCA tool or SBOM generator
  • you must detect or mitigate Log4Shell quickly

When to avoid

  • you need runtime application security or WAF features rather than dependency scanning
  • you require a commercially supported SCA product with SLAs
  • your project is not on a supported language ecosystem like JavaScript or Java

Facets

service · maturity maintenance

security vulnerability-scanning dependency-audit cli developer-tools security developer-tools cli self-hosted sbom software-composition-analysis supply-chain-security cve-scanning log4shell github-app tokenization devsecops devops web-server docker nodejs

1 source

Member repositories

RepositoryRoleHealth v2
lunasec-io/lunasecmain23

For agents

markdown · JSON · MCP: product_card(name="lunasec-io/lunasec")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem