- [ ] Extend the it-depends API to associate vulnerabilities with packages - [ ] Use [Google OSV](https://osv.dev/) as a data source to automatically assign vulnerabilities to packages - [ ] Provide a command line option similar to `npm audit` that reports the known vulnerabilities for a project
npm auditthat reports the known vulnerabilities for a project