Know when a vulnerable npm package lands in your stack

Track the packages your project actually uses. Get Telegram alerts daily or in real time when a published advisory matches your dependency versions.

Advisory published
Affected version found
Telegram alert sent
See Sample Alerts

Works with package.json and lockfile-based dependency graphs

Realtime alert

lodash vulnerability matched

High

Project: dashboard-web

Installed: lodash 4.17.20

Affected: < 4.17.21

Fixed in: 4.17.21

Telegram message includes severity, affected range, fixed version, and a direct nudge to check if you need an upgrade now.

Daily digest

minimatch

Used in bot-worker · Medium severity

upgrade available

ws

Used in api-server · No action needed

not affected

How It Works

Simple monitoring for the dependencies you already ship

1

Connect a project

Add a repo, upload dependency files, or point to the package list you want monitored.

2

Match advisories to versions

When npm advisories land, the service checks whether your installed version range is actually affected.

3

Receive Telegram alerts

Get a quiet daily digest or immediate alerts with package name, severity, fixed version, and impact.

Why teams use Pkg Alerts

Security signal without dependency panic

Tells you if you are actually affected

Not every new advisory matters to every project. The alert checks the versions you use before bothering you.

Telegram-first delivery

Alerts show up where devs already pay attention: chats, team groups, and private monitoring channels.

Daily digests and instant alerts

Use real-time notifications for critical issues and a calmer summary for the rest.

Built for comfort, not fear

The goal is simple: when a version has issues, you instantly know whether you have it or you don't.

Vulnerability detected

serialize-javascript < 6.0.2 can lead to XSS in affected builds

Telegram alert preview

lodash in dashboard-web is vulnerable. Installed: 4.17.20 · Affected: < 4.17.21 · Fixed: 4.17.21 · Severity: High

Choose your alert mode

Stay informed at the pace your team wants

Daily Digest

Calm by default

A clean summary of what changed and what matters

  • One Telegram digest per day
  • New advisories grouped by project
  • Affected vs not affected called out clearly
  • Great for solo builders and quieter teams
View the Flow
Fastest

Realtime + Digest

Immediate when it counts

For teams that want critical issues surfaced right away

  • Instant alerts for new matching advisories
  • Daily summary still included
  • Fixed version and severity in every message
  • Ideal for shared engineering channels
Preview Alerts

Ready to stop guessing about npm advisories?

When a vulnerable version gets published, your team should know if it affects your project within minutes.

Explore Alert Modes

Built for teams that want confidence, not more noise