PDF document

Node Audit Analyzer – OWASP Dependency-Check

The analyzer submits the lock files to the NPM Audit API for analysis, returning a list of advisories which get incorporated into the dependency check reports. This analyzer is enabled by default and requires that the machine performing the analysis can reach out to the Internet.

Source: dependency-check.github.io