Overview
Optional first-party modules for @absolutejs/vulnerabilities. Each module remains an independently versioned npm package; this repository is their source monorepo.
@absolutejs/vulnerabilities-modulesworkspacealphaPlatform & InfraOptional first-party modules for AbsoluteJS vulnerability management.
git clone https://github.com/absolutejs/vulnerabilities-modules.gitOptional first-party modules for @absolutejs/vulnerabilities. Each module remains an independently versioned npm package; this repository is their source monorepo.
Workspace — Package — Role
report/ — @absolutejs/vulnerabilities-report — Deterministic evidence-backed reporting
worker/ — @absolutejs/vulnerabilities-worker — Continuous vulnerability intelligence orchestration
witness/ — @absolutejs/vulnerabilities-witness — Independently deployable transparency witness
The Witness container remains independently deployable. Its package-local lock file is retained so witness/Dockerfile can build from the witness/ context. Each workspace retains its own license and changelog.
3 public packages and 0 private workspace projects are versioned and developed together.
Outcomes
Optional first-party modules for @absolutejs/vulnerabilities. Each module remains an independently versioned npm package; this repository is their source monorepo.
Workspace — Package — Role
The Witness container remains independently deployable. Its package-local lock file is retained so witness/Dockerfile can build from the witness/ context. Each workspace retains its own license and changelog.
Hardening checklist
Follow in order
Working example for Development.
bun install
bun run typecheck
bun run test
bun run build3 public packages and 0 private workspace projects are maintained in this repository.
Public package — Deterministic, evidence-backed, print-ready HTML reports for AbsoluteJS vulnerability management.
Public package — Independent durable transparency witness with rollback, equivocation, key-rotation, and HTTP service primitives for AbsoluteJS vulnerability evidence.
Public package — Continuous feed refresh, inventory correlation, VEX, risk, remediation, leases, health, and metrics for AbsoluteJS vulnerability management.
Scripts declared by this project’s package manifest.