sector27-gmbh/laravel-npm-health-checks

A Laravel Health check for npm audit advisories.
1,250
Install
composer require sector27-gmbh/laravel-npm-health-checks
Latest Version:v0.1.1
PHP:^8.4
License:MIT
Last Updated:Aug 18, 2026
Links: GitHub  ·  Packagist
Maintainer: samsc27

Laravel npm Health Checks

Latest Version on Packagist GitHub Tests Action Status GitHub Code Style Action Status Total Downloads

This package adds a Laravel Health check for npm security advisories. It runs npm audit --json, stores the parsed audit output as check meta, and reports warnings or failures based on configurable severity thresholds.

Installation

You can install the package via composer:

composer require sector27-gmbh/laravel-npm-health-checks

You can publish the config file with:

php artisan vendor:publish --tag="laravel-npm-health-checks-config"

This is the contents of the published config file:

return [
    'paths' => [
        base_path(),
    ],

    'include_dev_dependencies' => false,

    'warning_threshold' => 'moderate',

    'failure_threshold' => 'high',

    'npm_binary' => 'npm',

    'timeout' => 60,
];

Usage

Register the check with Laravel Health:

use Sector27\LaravelNpmHealthChecks\NpmAuditCheck;
use Spatie\Health\Facades\Health;

Health::checks([
    NpmAuditCheck::new(),
]);

By default, the check audits production dependencies in your application root. It returns ok without a notification message when no vulnerabilities meet the warning threshold.

You may configure the check fluently:

Health::checks([
    NpmAuditCheck::new()
        ->atPaths([
            base_path(),
            base_path('resources/frontend'),
        ])
        ->includeDevDependencies()
        ->warnWhenSeverityIsAtLeast('moderate')
        ->failWhenSeverityIsAtLeast('high')
        ->timeout(120),
]);

Testing

composer test

Changelog

Please see CHANGELOG for more information on what has changed recently.

Security Vulnerabilities

Please review our security policy on how to report security vulnerabilities.

Credits

License

The MIT License (MIT). Please see License File for more information.

Related Packages

williamug/audited

The only Laravel audit package that ships a complete admin UI — Livewire table,...

854 2
ivqonsanada/enlightn

Fork of Enlightn - Your performance & security consultant, an artisan command aw...

72,516 1
kodeine/laravel-acl

Light-weight role-based permissions for Laravel 5 built in Auth system.

363,834 774