Repository files navigation

verimu

The infrastructure layer that makes CRA compliance easier to manage in engineering workflows. verimu helps teams automate SBOM generation, dependency intelligence, and vulnerability visibility across CI/CD pipelines.

Documentation and Website

App Platform

Supported CI / CD Platforms

The core scanning pipeline is CI-agnostic — it works in any environment with Node.js 20+. Example CI configs are provided in the ci-examples/ directory.

  • GitHub Actions (.github/workflows/ci.yml, .github/workflows/publish-npm.yml)
  • GitLab CI (ci-examples/gitlab-ci.yml)
  • Bitbucket Pipelines (ci-examples/bitbucket-pipelines.yml)

Supported Package Ecosystems

  • npm (package-lock.json)
  • yarn (yarn.lock)
  • pnpm (pnpm-lock.yaml)
  • NuGet (packages.lock.json)
  • pip (requirements.txt, Pipfile.lock)
  • Cargo (Cargo.lock)
  • Maven (pom.xml + dependency-tree.txt or mvn on PATH)
  • Go (go.sum)
  • Ruby (Gemfile.lock)
  • Composer (composer.lock)

Usage Context Analysis (Vulnerable Package Evidence)

When CVEs are found, verimu now runs a usage-context stage that scans source code and records where vulnerable packages appear (imports/requires and nearby call sites).
This stage is fail-open (non-fatal), and writes a machine-friendly artifact beside the SBOM:

  • *.usage-context.json

You can configure snippet context size with:

  • --context-lines <n> (default 4, clamped to 0..20)
  • Programmatic API: numContextLines?: number in scan() config

Analyzer Matrix (v0.0.19)

Ecosystem in VerimuAnalyzer strategyEvidence targets
npm / yarn / pnpmBabel parse + traverseimports/requires/exports + nearby calls
denoBabel parse + traverseimports + nearby calls
pip / poetry / uvPython source pattern analyzerimport / from ... import ... + calls
mavenJava source pattern analyzerimport + method/static calls
nugetC# source pattern analyzerusing + namespace/type calls
cargoRust source pattern analyzeruse / extern crate + ::/method calls
goGo source pattern analyzerimport + selector/function calls
rubyRuby source pattern analyzerrequire / include + constant/module calls
composer (PHP)PHP source pattern analyzeruse / require + static/constructor calls

All analyzers are fail-open (non-fatal): a parser/runtime issue only downgrades usage-context status for that ecosystem/package and never aborts SBOM/CVE scanning.

Development

To run the tests, use:

npm test

Releasing to npm (Tag Pipelines)

verimu can publish from GitHub Actions, GitLab CI, and Bitbucket Pipelines when a semver tag is pushed. Each pipeline validates:

  • tag is semver (i.e. 1.2.3 without a v prefix)
  • tag version must match package.json version
  • tagged commit exists on main

Publish credentials

  • GitHub Actions (.github/workflows/publish-npm.yml): uses npm Trusted Publishing (OIDC), so NO NPM_TOKEN secret is required.
  • GitLab and Bitbucket pipelines in this repo still use NPM_TOKEN (.gitlab-ci.yml, bitbucket-pipelines.yml).

Recommended release flow

  1. Bump version on main with npm (this updates package.json and package-lock.json, then creates a git tag):
npm version patch
  1. Push commit and tag:
git push origin main --follow-tags
  1. Your CI provider runs the publish job on that tag and releases to npm.

Why this avoids version conflicts

The source of truth remains the version committed on main. The tag is only a release trigger for that exact versioned commit. You should not tag arbitrary commits with a new version string that is not already committed in package.json.

Maven Scanner Notes

The Maven scanner needs resolved dependencies. Since Maven has no lockfile, it uses two strategies:

  1. Pre-generated dependency tree (recommended for CI): Run mvn dependency:list -DoutputFile=dependency-tree.txt -DappendOutput=true before scanning.
  2. Auto-detect: If mvn is on $PATH, the scanner runs mvn dependency:list automatically.

Three CI / CD Pipelines as Self Check on the verimu package itself

There is a bitbucket-pipelines.yml and .gitlab-ci.yml in the root of the project, as well as a .github/workflows/ci.yml file, all of which run verimu against itself in each of the 3 frameworks we support (GitHub Actions, GitLab CI, Bitbucket Pipelines). The tests should pass in all 3 environments, confirming that verimu can successfully scan its own dependencies and produce a report.

Tag-based npm release automation in GitHub Actions is handled by .github/workflows/publish-npm.yml, so this repo remains a working cross-provider reference for both scanning and publishing.

About

The npm package for automatically identifying software frameworks within CI/CD and producing CRA-compliant SBOMs.

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

verimu

The infrastructure layer that makes CRA compliance easier to manage in engineering workflows. verimu helps teams automate SBOM generation, dependency intelligence, and vulnerability visibility across CI/CD pipelines.

Documentation and Website

App Platform

Supported CI / CD Platforms

The core scanning pipeline is CI-agnostic — it works in any environment with Node.js 20+. Example CI configs are provided in the ci-examples/ directory.

  • GitHub Actions (.github/workflows/ci.yml, .github/workflows/publish-npm.yml)
  • GitLab CI (ci-examples/gitlab-ci.yml)
  • Bitbucket Pipelines (ci-examples/bitbucket-pipelines.yml)

Supported Package Ecosystems

  • npm (package-lock.json)
  • yarn (yarn.lock)
  • pnpm (pnpm-lock.yaml)
  • NuGet (packages.lock.json)
  • pip (requirements.txt, Pipfile.lock)
  • Cargo (Cargo.lock)
  • Maven (pom.xml + dependency-tree.txt or mvn on PATH)
  • Go (go.sum)
  • Ruby (Gemfile.lock)
  • Composer (composer.lock)

Usage Context Analysis (Vulnerable Package Evidence)

When CVEs are found, verimu now runs a usage-context stage that scans source code and records where vulnerable packages appear (imports/requires and nearby call sites).
This stage is fail-open (non-fatal), and writes a machine-friendly artifact beside the SBOM:

  • *.usage-context.json

You can configure snippet context size with:

  • --context-lines <n> (default 4, clamped to 0..20)
  • Programmatic API: numContextLines?: number in scan() config

Analyzer Matrix (v0.0.19)

Ecosystem in VerimuAnalyzer strategyEvidence targets
npm / yarn / pnpmBabel parse + traverseimports/requires/exports + nearby calls
denoBabel parse + traverseimports + nearby calls
pip / poetry / uvPython source pattern analyzerimport / from ... import ... + calls
mavenJava source pattern analyzerimport + method/static calls
nugetC# source pattern analyzerusing + namespace/type calls
cargoRust source pattern analyzeruse / extern crate + ::/method calls
goGo source pattern analyzerimport + selector/function calls
rubyRuby source pattern analyzerrequire / include + constant/module calls
composer (PHP)PHP source pattern analyzeruse / require + static/constructor calls

All analyzers are fail-open (non-fatal): a parser/runtime issue only downgrades usage-context status for that ecosystem/package and never aborts SBOM/CVE scanning.

Development

To run the tests, use:

npm test

Releasing to npm (Tag Pipelines)

verimu can publish from GitHub Actions, GitLab CI, and Bitbucket Pipelines when a semver tag is pushed. Each pipeline validates:

  • tag is semver (i.e. 1.2.3 without a v prefix)
  • tag version must match package.json version
  • tagged commit exists on main

Publish credentials

  • GitHub Actions (.github/workflows/publish-npm.yml): uses npm Trusted Publishing (OIDC), so NO NPM_TOKEN secret is required.
  • GitLab and Bitbucket pipelines in this repo still use NPM_TOKEN (.gitlab-ci.yml, bitbucket-pipelines.yml).

Recommended release flow

  1. Bump version on main with npm (this updates package.json and package-lock.json, then creates a git tag):
npm version patch
  1. Push commit and tag:
git push origin main --follow-tags
  1. Your CI provider runs the publish job on that tag and releases to npm.

Why this avoids version conflicts

The source of truth remains the version committed on main. The tag is only a release trigger for that exact versioned commit. You should not tag arbitrary commits with a new version string that is not already committed in package.json.

Maven Scanner Notes

The Maven scanner needs resolved dependencies. Since Maven has no lockfile, it uses two strategies:

  1. Pre-generated dependency tree (recommended for CI): Run mvn dependency:list -DoutputFile=dependency-tree.txt -DappendOutput=true before scanning.
  2. Auto-detect: If mvn is on $PATH, the scanner runs mvn dependency:list automatically.

Three CI / CD Pipelines as Self Check on the verimu package itself

There is a bitbucket-pipelines.yml and .gitlab-ci.yml in the root of the project, as well as a .github/workflows/ci.yml file, all of which run verimu against itself in each of the 3 frameworks we support (GitHub Actions, GitLab CI, Bitbucket Pipelines). The tests should pass in all 3 environments, confirming that verimu can successfully scan its own dependencies and produce a report.

Tag-based npm release automation in GitHub Actions is handled by .github/workflows/publish-npm.yml, so this repo remains a working cross-provider reference for both scanning and publishing.

About

The npm package for automatically identifying software frameworks within CI/CD and producing CRA-compliant SBOMs.

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

verimu

The infrastructure layer that makes CRA compliance easier to manage in engineering workflows. verimu helps teams automate SBOM generation, dependency intelligence, and vulnerability visibility across CI/CD pipelines.

Documentation and Website

App Platform

Supported CI / CD Platforms

The core scanning pipeline is CI-agnostic — it works in any environment with Node.js 20+. Example CI configs are provided in the ci-examples/ directory.

  • GitHub Actions (.github/workflows/ci.yml, .github/workflows/publish-npm.yml)
  • GitLab CI (ci-examples/gitlab-ci.yml)
  • Bitbucket Pipelines (ci-examples/bitbucket-pipelines.yml)

Supported Package Ecosystems

  • npm (package-lock.json)
  • yarn (yarn.lock)
  • pnpm (pnpm-lock.yaml)
  • NuGet (packages.lock.json)
  • pip (requirements.txt, Pipfile.lock)
  • Cargo (Cargo.lock)
  • Maven (pom.xml + dependency-tree.txt or mvn on PATH)
  • Go (go.sum)
  • Ruby (Gemfile.lock)
  • Composer (composer.lock)

Usage Context Analysis (Vulnerable Package Evidence)

When CVEs are found, verimu now runs a usage-context stage that scans source code and records where vulnerable packages appear (imports/requires and nearby call sites).
This stage is fail-open (non-fatal), and writes a machine-friendly artifact beside the SBOM:

  • *.usage-context.json

You can configure snippet context size with:

  • --context-lines <n> (default 4, clamped to 0..20)
  • Programmatic API: numContextLines?: number in scan() config

Analyzer Matrix (v0.0.19)

Ecosystem in VerimuAnalyzer strategyEvidence targets
npm / yarn / pnpmBabel parse + traverseimports/requires/exports + nearby calls
denoBabel parse + traverseimports + nearby calls
pip / poetry / uvPython source pattern analyzerimport / from ... import ... + calls
mavenJava source pattern analyzerimport + method/static calls
nugetC# source pattern analyzerusing + namespace/type calls
cargoRust source pattern analyzeruse / extern crate + ::/method calls
goGo source pattern analyzerimport + selector/function calls
rubyRuby source pattern analyzerrequire / include + constant/module calls
composer (PHP)PHP source pattern analyzeruse / require + static/constructor calls

All analyzers are fail-open (non-fatal): a parser/runtime issue only downgrades usage-context status for that ecosystem/package and never aborts SBOM/CVE scanning.

Development

To run the tests, use:

npm test

Releasing to npm (Tag Pipelines)

verimu can publish from GitHub Actions, GitLab CI, and Bitbucket Pipelines when a semver tag is pushed. Each pipeline validates:

  • tag is semver (i.e. 1.2.3 without a v prefix)
  • tag version must match package.json version
  • tagged commit exists on main

Publish credentials

  • GitHub Actions (.github/workflows/publish-npm.yml): uses npm Trusted Publishing (OIDC), so NO NPM_TOKEN secret is required.
  • GitLab and Bitbucket pipelines in this repo still use NPM_TOKEN (.gitlab-ci.yml, bitbucket-pipelines.yml).

Recommended release flow

  1. Bump version on main with npm (this updates package.json and package-lock.json, then creates a git tag):
npm version patch
  1. Push commit and tag:
git push origin main --follow-tags
  1. Your CI provider runs the publish job on that tag and releases to npm.

Why this avoids version conflicts

The source of truth remains the version committed on main. The tag is only a release trigger for that exact versioned commit. You should not tag arbitrary commits with a new version string that is not already committed in package.json.

Maven Scanner Notes

The Maven scanner needs resolved dependencies. Since Maven has no lockfile, it uses two strategies:

  1. Pre-generated dependency tree (recommended for CI): Run mvn dependency:list -DoutputFile=dependency-tree.txt -DappendOutput=true before scanning.
  2. Auto-detect: If mvn is on $PATH, the scanner runs mvn dependency:list automatically.

Three CI / CD Pipelines as Self Check on the verimu package itself

There is a bitbucket-pipelines.yml and .gitlab-ci.yml in the root of the project, as well as a .github/workflows/ci.yml file, all of which run verimu against itself in each of the 3 frameworks we support (GitHub Actions, GitLab CI, Bitbucket Pipelines). The tests should pass in all 3 environments, confirming that verimu can successfully scan its own dependencies and produce a report.

Tag-based npm release automation in GitHub Actions is handled by .github/workflows/publish-npm.yml, so this repo remains a working cross-provider reference for both scanning and publishing.

About

The npm package for automatically identifying software frameworks within CI/CD and producing CRA-compliant SBOMs.

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

verimu

The infrastructure layer that makes CRA compliance easier to manage in engineering workflows. verimu helps teams automate SBOM generation, dependency intelligence, and vulnerability visibility across CI/CD pipelines.

Documentation and Website

App Platform

Supported CI / CD Platforms

The core scanning pipeline is CI-agnostic — it works in any environment with Node.js 20+. Example CI configs are provided in the ci-examples/ directory.

  • GitHub Actions (.github/workflows/ci.yml, .github/workflows/publish-npm.yml)
  • GitLab CI (ci-examples/gitlab-ci.yml)
  • Bitbucket Pipelines (ci-examples/bitbucket-pipelines.yml)

Supported Package Ecosystems

  • npm (package-lock.json)
  • yarn (yarn.lock)
  • pnpm (pnpm-lock.yaml)
  • NuGet (packages.lock.json)
  • pip (requirements.txt, Pipfile.lock)
  • Cargo (Cargo.lock)
  • Maven (pom.xml + dependency-tree.txt or mvn on PATH)
  • Go (go.sum)
  • Ruby (Gemfile.lock)
  • Composer (composer.lock)

Usage Context Analysis (Vulnerable Package Evidence)

When CVEs are found, verimu now runs a usage-context stage that scans source code and records where vulnerable packages appear (imports/requires and nearby call sites).
This stage is fail-open (non-fatal), and writes a machine-friendly artifact beside the SBOM:

  • *.usage-context.json

You can configure snippet context size with:

  • --context-lines <n> (default 4, clamped to 0..20)
  • Programmatic API: numContextLines?: number in scan() config

Analyzer Matrix (v0.0.19)

Ecosystem in VerimuAnalyzer strategyEvidence targets
npm / yarn / pnpmBabel parse + traverseimports/requires/exports + nearby calls
denoBabel parse + traverseimports + nearby calls
pip / poetry / uvPython source pattern analyzerimport / from ... import ... + calls
mavenJava source pattern analyzerimport + method/static calls
nugetC# source pattern analyzerusing + namespace/type calls
cargoRust source pattern analyzeruse / extern crate + ::/method calls
goGo source pattern analyzerimport + selector/function calls
rubyRuby source pattern analyzerrequire / include + constant/module calls
composer (PHP)PHP source pattern analyzeruse / require + static/constructor calls

All analyzers are fail-open (non-fatal): a parser/runtime issue only downgrades usage-context status for that ecosystem/package and never aborts SBOM/CVE scanning.

Development

To run the tests, use:

npm test

Releasing to npm (Tag Pipelines)

verimu can publish from GitHub Actions, GitLab CI, and Bitbucket Pipelines when a semver tag is pushed. Each pipeline validates:

  • tag is semver (i.e. 1.2.3 without a v prefix)
  • tag version must match package.json version
  • tagged commit exists on main

Publish credentials

  • GitHub Actions (.github/workflows/publish-npm.yml): uses npm Trusted Publishing (OIDC), so NO NPM_TOKEN secret is required.
  • GitLab and Bitbucket pipelines in this repo still use NPM_TOKEN (.gitlab-ci.yml, bitbucket-pipelines.yml).

Recommended release flow

  1. Bump version on main with npm (this updates package.json and package-lock.json, then creates a git tag):
npm version patch
  1. Push commit and tag:
git push origin main --follow-tags
  1. Your CI provider runs the publish job on that tag and releases to npm.

Why this avoids version conflicts

The source of truth remains the version committed on main. The tag is only a release trigger for that exact versioned commit. You should not tag arbitrary commits with a new version string that is not already committed in package.json.

Maven Scanner Notes

The Maven scanner needs resolved dependencies. Since Maven has no lockfile, it uses two strategies:

  1. Pre-generated dependency tree (recommended for CI): Run mvn dependency:list -DoutputFile=dependency-tree.txt -DappendOutput=true before scanning.
  2. Auto-detect: If mvn is on $PATH, the scanner runs mvn dependency:list automatically.

Three CI / CD Pipelines as Self Check on the verimu package itself

There is a bitbucket-pipelines.yml and .gitlab-ci.yml in the root of the project, as well as a .github/workflows/ci.yml file, all of which run verimu against itself in each of the 3 frameworks we support (GitHub Actions, GitLab CI, Bitbucket Pipelines). The tests should pass in all 3 environments, confirming that verimu can successfully scan its own dependencies and produce a report.

Tag-based npm release automation in GitHub Actions is handled by .github/workflows/publish-npm.yml, so this repo remains a working cross-provider reference for both scanning and publishing.

About

The npm package for automatically identifying software frameworks within CI/CD and producing CRA-compliant SBOMs.

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

verimu

The infrastructure layer that makes CRA compliance easier to manage in engineering workflows. verimu helps teams automate SBOM generation, dependency intelligence, and vulnerability visibility across CI/CD pipelines.

Documentation and Website

App Platform

Supported CI / CD Platforms

The core scanning pipeline is CI-agnostic — it works in any environment with Node.js 20+. Example CI configs are provided in the ci-examples/ directory.

  • GitHub Actions (.github/workflows/ci.yml, .github/workflows/publish-npm.yml)
  • GitLab CI (ci-examples/gitlab-ci.yml)
  • Bitbucket Pipelines (ci-examples/bitbucket-pipelines.yml)

Supported Package Ecosystems

  • npm (package-lock.json)
  • yarn (yarn.lock)
  • pnpm (pnpm-lock.yaml)
  • NuGet (packages.lock.json)
  • pip (requirements.txt, Pipfile.lock)
  • Cargo (Cargo.lock)
  • Maven (pom.xml + dependency-tree.txt or mvn on PATH)
  • Go (go.sum)
  • Ruby (Gemfile.lock)
  • Composer (composer.lock)

Usage Context Analysis (Vulnerable Package Evidence)

When CVEs are found, verimu now runs a usage-context stage that scans source code and records where vulnerable packages appear (imports/requires and nearby call sites).
This stage is fail-open (non-fatal), and writes a machine-friendly artifact beside the SBOM:

  • *.usage-context.json

You can configure snippet context size with:

  • --context-lines <n> (default 4, clamped to 0..20)
  • Programmatic API: numContextLines?: number in scan() config

Analyzer Matrix (v0.0.19)

Ecosystem in VerimuAnalyzer strategyEvidence targets
npm / yarn / pnpmBabel parse + traverseimports/requires/exports + nearby calls
denoBabel parse + traverseimports + nearby calls
pip / poetry / uvPython source pattern analyzerimport / from ... import ... + calls
mavenJava source pattern analyzerimport + method/static calls
nugetC# source pattern analyzerusing + namespace/type calls
cargoRust source pattern analyzeruse / extern crate + ::/method calls
goGo source pattern analyzerimport + selector/function calls
rubyRuby source pattern analyzerrequire / include + constant/module calls
composer (PHP)PHP source pattern analyzeruse / require + static/constructor calls

All analyzers are fail-open (non-fatal): a parser/runtime issue only downgrades usage-context status for that ecosystem/package and never aborts SBOM/CVE scanning.

Development

To run the tests, use:

npm test

Releasing to npm (Tag Pipelines)

verimu can publish from GitHub Actions, GitLab CI, and Bitbucket Pipelines when a semver tag is pushed. Each pipeline validates:

  • tag is semver (i.e. 1.2.3 without a v prefix)
  • tag version must match package.json version
  • tagged commit exists on main

Publish credentials

  • GitHub Actions (.github/workflows/publish-npm.yml): uses npm Trusted Publishing (OIDC), so NO NPM_TOKEN secret is required.
  • GitLab and Bitbucket pipelines in this repo still use NPM_TOKEN (.gitlab-ci.yml, bitbucket-pipelines.yml).

Recommended release flow

  1. Bump version on main with npm (this updates package.json and package-lock.json, then creates a git tag):
npm version patch
  1. Push commit and tag:
git push origin main --follow-tags
  1. Your CI provider runs the publish job on that tag and releases to npm.

Why this avoids version conflicts

The source of truth remains the version committed on main. The tag is only a release trigger for that exact versioned commit. You should not tag arbitrary commits with a new version string that is not already committed in package.json.

Maven Scanner Notes

The Maven scanner needs resolved dependencies. Since Maven has no lockfile, it uses two strategies:

  1. Pre-generated dependency tree (recommended for CI): Run mvn dependency:list -DoutputFile=dependency-tree.txt -DappendOutput=true before scanning.
  2. Auto-detect: If mvn is on $PATH, the scanner runs mvn dependency:list automatically.

Three CI / CD Pipelines as Self Check on the verimu package itself

There is a bitbucket-pipelines.yml and .gitlab-ci.yml in the root of the project, as well as a .github/workflows/ci.yml file, all of which run verimu against itself in each of the 3 frameworks we support (GitHub Actions, GitLab CI, Bitbucket Pipelines). The tests should pass in all 3 environments, confirming that verimu can successfully scan its own dependencies and produce a report.

Tag-based npm release automation in GitHub Actions is handled by .github/workflows/publish-npm.yml, so this repo remains a working cross-provider reference for both scanning and publishing.

About

The npm package for automatically identifying software frameworks within CI/CD and producing CRA-compliant SBOMs.

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

verimu

The infrastructure layer that makes CRA compliance easier to manage in engineering workflows. verimu helps teams automate SBOM generation, dependency intelligence, and vulnerability visibility across CI/CD pipelines.

Documentation and Website

App Platform

Supported CI / CD Platforms

The core scanning pipeline is CI-agnostic — it works in any environment with Node.js 20+. Example CI configs are provided in the ci-examples/ directory.

  • GitHub Actions (.github/workflows/ci.yml, .github/workflows/publish-npm.yml)
  • GitLab CI (ci-examples/gitlab-ci.yml)
  • Bitbucket Pipelines (ci-examples/bitbucket-pipelines.yml)

Supported Package Ecosystems

  • npm (package-lock.json)
  • yarn (yarn.lock)
  • pnpm (pnpm-lock.yaml)
  • NuGet (packages.lock.json)
  • pip (requirements.txt, Pipfile.lock)
  • Cargo (Cargo.lock)
  • Maven (pom.xml + dependency-tree.txt or mvn on PATH)
  • Go (go.sum)
  • Ruby (Gemfile.lock)
  • Composer (composer.lock)

Usage Context Analysis (Vulnerable Package Evidence)

When CVEs are found, verimu now runs a usage-context stage that scans source code and records where vulnerable packages appear (imports/requires and nearby call sites).
This stage is fail-open (non-fatal), and writes a machine-friendly artifact beside the SBOM:

  • *.usage-context.json

You can configure snippet context size with:

  • --context-lines <n> (default 4, clamped to 0..20)
  • Programmatic API: numContextLines?: number in scan() config

Analyzer Matrix (v0.0.19)

Ecosystem in VerimuAnalyzer strategyEvidence targets
npm / yarn / pnpmBabel parse + traverseimports/requires/exports + nearby calls
denoBabel parse + traverseimports + nearby calls
pip / poetry / uvPython source pattern analyzerimport / from ... import ... + calls
mavenJava source pattern analyzerimport + method/static calls
nugetC# source pattern analyzerusing + namespace/type calls
cargoRust source pattern analyzeruse / extern crate + ::/method calls
goGo source pattern analyzerimport + selector/function calls
rubyRuby source pattern analyzerrequire / include + constant/module calls
composer (PHP)PHP source pattern analyzeruse / require + static/constructor calls

All analyzers are fail-open (non-fatal): a parser/runtime issue only downgrades usage-context status for that ecosystem/package and never aborts SBOM/CVE scanning.

Development

To run the tests, use:

npm test

Releasing to npm (Tag Pipelines)

verimu can publish from GitHub Actions, GitLab CI, and Bitbucket Pipelines when a semver tag is pushed. Each pipeline validates:

  • tag is semver (i.e. 1.2.3 without a v prefix)
  • tag version must match package.json version
  • tagged commit exists on main

Publish credentials

  • GitHub Actions (.github/workflows/publish-npm.yml): uses npm Trusted Publishing (OIDC), so NO NPM_TOKEN secret is required.
  • GitLab and Bitbucket pipelines in this repo still use NPM_TOKEN (.gitlab-ci.yml, bitbucket-pipelines.yml).

Recommended release flow

  1. Bump version on main with npm (this updates package.json and package-lock.json, then creates a git tag):
npm version patch
  1. Push commit and tag:
git push origin main --follow-tags
  1. Your CI provider runs the publish job on that tag and releases to npm.

Why this avoids version conflicts

The source of truth remains the version committed on main. The tag is only a release trigger for that exact versioned commit. You should not tag arbitrary commits with a new version string that is not already committed in package.json.

Maven Scanner Notes

The Maven scanner needs resolved dependencies. Since Maven has no lockfile, it uses two strategies:

  1. Pre-generated dependency tree (recommended for CI): Run mvn dependency:list -DoutputFile=dependency-tree.txt -DappendOutput=true before scanning.
  2. Auto-detect: If mvn is on $PATH, the scanner runs mvn dependency:list automatically.

Three CI / CD Pipelines as Self Check on the verimu package itself

There is a bitbucket-pipelines.yml and .gitlab-ci.yml in the root of the project, as well as a .github/workflows/ci.yml file, all of which run verimu against itself in each of the 3 frameworks we support (GitHub Actions, GitLab CI, Bitbucket Pipelines). The tests should pass in all 3 environments, confirming that verimu can successfully scan its own dependencies and produce a report.

Tag-based npm release automation in GitHub Actions is handled by .github/workflows/publish-npm.yml, so this repo remains a working cross-provider reference for both scanning and publishing.

About

The npm package for automatically identifying software frameworks within CI/CD and producing CRA-compliant SBOMs.

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

verimu

The infrastructure layer that makes CRA compliance easier to manage in engineering workflows. verimu helps teams automate SBOM generation, dependency intelligence, and vulnerability visibility across CI/CD pipelines.

Documentation and Website

App Platform

Supported CI / CD Platforms

The core scanning pipeline is CI-agnostic — it works in any environment with Node.js 20+. Example CI configs are provided in the ci-examples/ directory.

  • GitHub Actions (.github/workflows/ci.yml, .github/workflows/publish-npm.yml)
  • GitLab CI (ci-examples/gitlab-ci.yml)
  • Bitbucket Pipelines (ci-examples/bitbucket-pipelines.yml)

Supported Package Ecosystems

  • npm (package-lock.json)
  • yarn (yarn.lock)
  • pnpm (pnpm-lock.yaml)
  • NuGet (packages.lock.json)
  • pip (requirements.txt, Pipfile.lock)
  • Cargo (Cargo.lock)
  • Maven (pom.xml + dependency-tree.txt or mvn on PATH)
  • Go (go.sum)
  • Ruby (Gemfile.lock)
  • Composer (composer.lock)

Usage Context Analysis (Vulnerable Package Evidence)

When CVEs are found, verimu now runs a usage-context stage that scans source code and records where vulnerable packages appear (imports/requires and nearby call sites).
This stage is fail-open (non-fatal), and writes a machine-friendly artifact beside the SBOM:

  • *.usage-context.json

You can configure snippet context size with:

  • --context-lines <n> (default 4, clamped to 0..20)
  • Programmatic API: numContextLines?: number in scan() config

Analyzer Matrix (v0.0.19)

Ecosystem in VerimuAnalyzer strategyEvidence targets
npm / yarn / pnpmBabel parse + traverseimports/requires/exports + nearby calls
denoBabel parse + traverseimports + nearby calls
pip / poetry / uvPython source pattern analyzerimport / from ... import ... + calls
mavenJava source pattern analyzerimport + method/static calls
nugetC# source pattern analyzerusing + namespace/type calls
cargoRust source pattern analyzeruse / extern crate + ::/method calls
goGo source pattern analyzerimport + selector/function calls
rubyRuby source pattern analyzerrequire / include + constant/module calls
composer (PHP)PHP source pattern analyzeruse / require + static/constructor calls

All analyzers are fail-open (non-fatal): a parser/runtime issue only downgrades usage-context status for that ecosystem/package and never aborts SBOM/CVE scanning.

Development

To run the tests, use:

npm test

Releasing to npm (Tag Pipelines)

verimu can publish from GitHub Actions, GitLab CI, and Bitbucket Pipelines when a semver tag is pushed. Each pipeline validates:

  • tag is semver (i.e. 1.2.3 without a v prefix)
  • tag version must match package.json version
  • tagged commit exists on main

Publish credentials

  • GitHub Actions (.github/workflows/publish-npm.yml): uses npm Trusted Publishing (OIDC), so NO NPM_TOKEN secret is required.
  • GitLab and Bitbucket pipelines in this repo still use NPM_TOKEN (.gitlab-ci.yml, bitbucket-pipelines.yml).

Recommended release flow

  1. Bump version on main with npm (this updates package.json and package-lock.json, then creates a git tag):
npm version patch
  1. Push commit and tag:
git push origin main --follow-tags
  1. Your CI provider runs the publish job on that tag and releases to npm.

Why this avoids version conflicts

The source of truth remains the version committed on main. The tag is only a release trigger for that exact versioned commit. You should not tag arbitrary commits with a new version string that is not already committed in package.json.

Maven Scanner Notes

The Maven scanner needs resolved dependencies. Since Maven has no lockfile, it uses two strategies:

  1. Pre-generated dependency tree (recommended for CI): Run mvn dependency:list -DoutputFile=dependency-tree.txt -DappendOutput=true before scanning.
  2. Auto-detect: If mvn is on $PATH, the scanner runs mvn dependency:list automatically.

Three CI / CD Pipelines as Self Check on the verimu package itself

There is a bitbucket-pipelines.yml and .gitlab-ci.yml in the root of the project, as well as a .github/workflows/ci.yml file, all of which run verimu against itself in each of the 3 frameworks we support (GitHub Actions, GitLab CI, Bitbucket Pipelines). The tests should pass in all 3 environments, confirming that verimu can successfully scan its own dependencies and produce a report.

Tag-based npm release automation in GitHub Actions is handled by .github/workflows/publish-npm.yml, so this repo remains a working cross-provider reference for both scanning and publishing.

About

The npm package for automatically identifying software frameworks within CI/CD and producing CRA-compliant SBOMs.

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

verimu

The infrastructure layer that makes CRA compliance easier to manage in engineering workflows. verimu helps teams automate SBOM generation, dependency intelligence, and vulnerability visibility across CI/CD pipelines.

Documentation and Website

App Platform

Supported CI / CD Platforms

The core scanning pipeline is CI-agnostic — it works in any environment with Node.js 20+. Example CI configs are provided in the ci-examples/ directory.

  • GitHub Actions (.github/workflows/ci.yml, .github/workflows/publish-npm.yml)
  • GitLab CI (ci-examples/gitlab-ci.yml)
  • Bitbucket Pipelines (ci-examples/bitbucket-pipelines.yml)

Supported Package Ecosystems

  • npm (package-lock.json)
  • yarn (yarn.lock)
  • pnpm (pnpm-lock.yaml)
  • NuGet (packages.lock.json)
  • pip (requirements.txt, Pipfile.lock)
  • Cargo (Cargo.lock)
  • Maven (pom.xml + dependency-tree.txt or mvn on PATH)
  • Go (go.sum)
  • Ruby (Gemfile.lock)
  • Composer (composer.lock)

Usage Context Analysis (Vulnerable Package Evidence)

When CVEs are found, verimu now runs a usage-context stage that scans source code and records where vulnerable packages appear (imports/requires and nearby call sites).
This stage is fail-open (non-fatal), and writes a machine-friendly artifact beside the SBOM:

  • *.usage-context.json

You can configure snippet context size with:

  • --context-lines <n> (default 4, clamped to 0..20)
  • Programmatic API: numContextLines?: number in scan() config

Analyzer Matrix (v0.0.19)

Ecosystem in VerimuAnalyzer strategyEvidence targets
npm / yarn / pnpmBabel parse + traverseimports/requires/exports + nearby calls
denoBabel parse + traverseimports + nearby calls
pip / poetry / uvPython source pattern analyzerimport / from ... import ... + calls
mavenJava source pattern analyzerimport + method/static calls
nugetC# source pattern analyzerusing + namespace/type calls
cargoRust source pattern analyzeruse / extern crate + ::/method calls
goGo source pattern analyzerimport + selector/function calls
rubyRuby source pattern analyzerrequire / include + constant/module calls
composer (PHP)PHP source pattern analyzeruse / require + static/constructor calls

All analyzers are fail-open (non-fatal): a parser/runtime issue only downgrades usage-context status for that ecosystem/package and never aborts SBOM/CVE scanning.

Development

To run the tests, use:

npm test

Releasing to npm (Tag Pipelines)

verimu can publish from GitHub Actions, GitLab CI, and Bitbucket Pipelines when a semver tag is pushed. Each pipeline validates:

  • tag is semver (i.e. 1.2.3 without a v prefix)
  • tag version must match package.json version
  • tagged commit exists on main

Publish credentials

  • GitHub Actions (.github/workflows/publish-npm.yml): uses npm Trusted Publishing (OIDC), so NO NPM_TOKEN secret is required.
  • GitLab and Bitbucket pipelines in this repo still use NPM_TOKEN (.gitlab-ci.yml, bitbucket-pipelines.yml).

Recommended release flow

  1. Bump version on main with npm (this updates package.json and package-lock.json, then creates a git tag):
npm version patch
  1. Push commit and tag:
git push origin main --follow-tags
  1. Your CI provider runs the publish job on that tag and releases to npm.

Why this avoids version conflicts

The source of truth remains the version committed on main. The tag is only a release trigger for that exact versioned commit. You should not tag arbitrary commits with a new version string that is not already committed in package.json.

Maven Scanner Notes

The Maven scanner needs resolved dependencies. Since Maven has no lockfile, it uses two strategies:

  1. Pre-generated dependency tree (recommended for CI): Run mvn dependency:list -DoutputFile=dependency-tree.txt -DappendOutput=true before scanning.
  2. Auto-detect: If mvn is on $PATH, the scanner runs mvn dependency:list automatically.

Three CI / CD Pipelines as Self Check on the verimu package itself

There is a bitbucket-pipelines.yml and .gitlab-ci.yml in the root of the project, as well as a .github/workflows/ci.yml file, all of which run verimu against itself in each of the 3 frameworks we support (GitHub Actions, GitLab CI, Bitbucket Pipelines). The tests should pass in all 3 environments, confirming that verimu can successfully scan its own dependencies and produce a report.

Tag-based npm release automation in GitHub Actions is handled by .github/workflows/publish-npm.yml, so this repo remains a working cross-provider reference for both scanning and publishing.

About

The npm package for automatically identifying software frameworks within CI/CD and producing CRA-compliant SBOMs.

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages