# lunasec-io/lunasec

LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and Builds. Protect yourself in 30 seconds with the LunaTrace GitHub App: https://github.com/marketplace/lunatrace-by-lunasec/

Repository: https://github.com/lunasec-io/lunasec
Canonical: https://ross.abutalabs.com/products/lunasec
Homepage: https://www.lunasec.io/
Language: TypeScript
License: NOASSERTION
License Family: other
Topics: tokenization, web-security, compliance, security, soc2, pci-dss, gdpr, zero-trust, devsecops, log4shell, dependency-analysis, scanning, cybersecurity, security-tools, scanning-tool, cve-scanning, sbom, sbom-generator, continuous-delivery, software-composition-analysis
Last push: 2024-05-02T03:35:48+00:00

## Health v2 (maintenance only)
Score: 23/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 1996, "days_push": 853, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1469, forks 167 (observed 2026-08-28T04:04:49.034009+00:00)

## What it is
LunaSec is an open-source supply chain security suite whose main product, LunaTrace, scans project dependencies for vulnerabilities like Log4Shell and reports them in GitHub pull requests and builds. The monorepo also includes a Log4Shell scanning/patching CLI and LunaDefend, a tokenization-based data protection suite.

## Use cases
- scan dependencies for CVEs in pull requests
- generate SBOMs for my projects
- find and patch Log4Shell in jars
- self-hosted alternative to Snyk or Dependabot
- monitor npm packages for vulnerabilities like node-ipc
- tokenize sensitive data to meet PCI and SOC2 compliance

## When to choose
- you want automated dependency vulnerability alerts integrated with GitHub PRs
- you need an open-source, self-hostable SCA tool or SBOM generator
- you must detect or mitigate Log4Shell quickly

## When to avoid
- you need runtime application security or WAF features rather than dependency scanning
- you require a commercially supported SCA product with SLAs
- your project is not on a supported language ecosystem like JavaScript or Java

## Facets
- artifact type: service
- maturity: maintenance
- function: security, vulnerability-scanning, dependency-audit, cli, developer-tools
- domain: security, developer-tools
- platform: cli, self-hosted
- tags: sbom, software-composition-analysis, supply-chain-security, cve-scanning, log4shell, github-app, tokenization, devsecops, devops, web-server, docker, nodejs

## Member repositories
- lunasec-io/lunasec (main) score 23

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:49.034009+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:34:53.658355+00:00, confidence not recorded.
  - readme: https://github.com/lunasec-io/lunasec (fetched 2026-08-28T04:04:49.034009+00:00, sha c643609f6cf1)
- Data as of 2026-08-30T08:39:29.467469+00:00.
