Skip to content(if available)orjump to list(if available)

Show HN: NPM-Audit-to-Report

Show HN: NPM-Audit-to-Report

5 comments

·March 23, 2025

thangngoc89

The README is kinda light on details. This is a utility written in Go that convert yarn’s audit file from json to Markdown for reporting as part of the CI pipeline.

I’m wondering if yarn’s audit is better than npm’s audit?

yehors

Actually, it's the same. As I understand they use one database.

cluckindan

Why not use

    npm audit --json 
and just pass it to a template?

yehors

Not easy it sounds. Generated file has JSONL and each has summary or advisory lines. My script just processes them to a Markdown in Go.

thangngoc89

The script seems to be invoking yarn audit --json and does the templating.