Overview
Feed and storage adapters for @absolutejs/vulnerabilities. Each adapter remains an independently versioned npm package; this repository is their source monorepo.
@absolutejs/vulnerabilities-adaptersworkspacealphaPlatform & InfraFeed and storage adapters for @absolutejs/vulnerabilities.
git clone https://github.com/absolutejs/vulnerabilities-adapters.gitFeed and storage adapters for @absolutejs/vulnerabilities. Each adapter remains an independently versioned npm package; this repository is their source monorepo.
Workspace — Package — Role
epss/ — @absolutejs/vulnerabilities-epss — FIRST EPSS scoring feed
kev/ — @absolutejs/vulnerabilities-kev — CISA Known Exploited Vulnerabilities feed
osv/ — @absolutejs/vulnerabilities-osv — OSV advisory feed
postgres/ — @absolutejs/vulnerabilities-postgres — PostgreSQL persistence
ubuntu/ — @absolutejs/vulnerabilities-ubuntu — Canonical Ubuntu advisory feed
The npm package names and version histories are unchanged by the move into this monorepo.
Each workspace retains its own license and changelog.
5 public packages and 0 private workspace projects are versioned and developed together.
Outcomes
Feed and storage adapters for @absolutejs/vulnerabilities. Each adapter remains an independently versioned npm package; this repository is their source monorepo.
Workspace — Package — Role
Each workspace retains its own license and changelog.
Hardening checklist
Follow in order
Working example for Development.
bun install
bun run typecheck
bun run test
bun run build5 public packages and 0 private workspace projects are maintained in this repository.
Public package — FIRST EPSS probability and percentile ingestion for AbsoluteJS vulnerability prioritization.
Public package — CISA Known Exploited Vulnerabilities catalog ingestion for AbsoluteJS.
Public package — Official OSV API ingestion and advisory normalization for AbsoluteJS vulnerability management.
Public package — Durable Postgres feeds, findings, alert incidents, policy history, delivery queues, remediation evidence, and risk assessments for AbsoluteJS vulnerability management.
Public package — Canonical Ubuntu OSV advisory ingestion for AbsoluteJS vulnerability management.
Scripts declared by this project’s package manifest.