a public repository, read by nittim
Is 7rulnik/source-map-js production ready?
What nittim read in this repository, and what it found. Public repository, public reading — sourced from its own code and dependency manifests, nothing else.
Consume and generate source maps.
JavaScript · 102 stars · last push September 30, 2026
7rulnik/source-map-js is a JavaScript repository that consumes and generates source maps. The codebase consists of 52 files that were all read during the scan.
The scan found evidence of vulnerable runtime dependencies. There are 17 vulnerable packages in the dependency tree. The vulnerable packages include braces, cross-spawn, decode-uri-component, json5, loader-utils, minimist, picomatch, sha.js, and underscore. braces has advisories GHSA-grv7-fg5c-xmjg and GHSA-vfj7-8cjw-p6xm. cross-spawn has advisory GHSA-3xgq-45jj-v275. decode-uri-component has advisory GHSA-w573-4hg7-7wgq. json5 has advisory GHSA-9c47-m6qq-7p4h. loader-utils has advisory GHSA-76p3-8jx3-jpfq. minimist has advisory GHSA-xvch-5gv4-984h. picomatch has advisory GHSA-c2c7-rcm5-vvqj. sha.js has advisory GHSA-95m3-7q98-8xr5. underscore has advisories GHSA-cf4h-3jhx-xvhq and GHSA-qpx9-hpmf-5gmw.
Developers should update the vulnerable dependencies to versions that address these advisories. After updating, rescan 7rulnik/source-map-js to confirm the vulnerabilities are resolved. Then run a full audit to understand the details of each issue and determine what changes are needed.
Written from nittim's own scan on October 10, 2026; rescanned when the repository changes.
No verdict. The rule-based check reports hard evidence, or reports that it found none. Neither is a judgment on whether this code is safe to ship.
What was read — rule-based scan
Rule-based checks run on nittim's servers — a secret scanner and a dependency check, no model in the path. The code reached those two and stopped there.
Read 52 of 52 eligible files. Commit b158388. 2026-10-10.
What the scanners found
- Committed secrets on production paths
- 0
- Vulnerable runtime dependencies
- 17
braces (GHSA-grv7-fg5c-xmjg, GHSA-vfj7-8cjw-p6xm), cross-spawn (GHSA-3xgq-45jj-v275), decode-uri-component (GHSA-w573-4hg7-7wgq), json5 (GHSA-9c47-m6qq-7p4h), loader-utils (GHSA-76p3-8jx3-jpfq), minimist (GHSA-xvch-5gv4-984h), picomatch (GHSA-c2c7-rcm5-vvqj), sha.js (GHSA-95m3-7q98-8xr5), underscore (GHSA-cf4h-3jhx-xvhq, GHSA-qpx9-hpmf-5gmw)
Run it yourself
Scan any public repository in seconds — no sign-in, no card. Audit it to have a model read the code. Loop the report into your assistant to get the fixes applied and re-checked.
Scan your own repoQuestions
- What did nittim read in 7rulnik/source-map-js?
- nittim read 52 of 52 eligible files in 7rulnik/source-map-js. The reading ran on October 10, 2026. It was taken at commit b158388.
- Did nittim find committed secrets or vulnerable dependencies in 7rulnik/source-map-js?
- The rule-based scan found 0 committed secrets and 17 vulnerable dependencies in 7rulnik/source-map-js. Affected: braces (GHSA-grv7-fg5c-xmjg, GHSA-vfj7-8cjw-p6xm), cross-spawn (GHSA-3xgq-45jj-v275), decode-uri-component (GHSA-w573-4hg7-7wgq), json5 (GHSA-9c47-m6qq-7p4h), loader-utils (GHSA-76p3-8jx3-jpfq), minimist (GHSA-xvch-5gv4-984h), picomatch (GHSA-c2c7-rcm5-vvqj), sha.js (GHSA-95m3-7q98-8xr5), underscore (GHSA-cf4h-3jhx-xvhq, GHSA-qpx9-hpmf-5gmw).
- Is 7rulnik/source-map-js production ready?
- A free scan is not a verdict. A full audit gives one.
More like this
- acornjs/acorn
- A11yance/aria-query
- fastify/fastify — High Risk
- axios/axios
- expressjs/express — High Risk
- debug-js/debug — Production Ready
More JavaScript repositories →
Add the badge to your README
[](https://nittim.com/library/7rulnik/source-map-js)