<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>Forem: CVERiskPilot</title>
    <description>The latest articles on Forem by CVERiskPilot (@cveriskpilot).</description>
    <link>https://forem.com/cveriskpilot</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3849832%2F1f9793e2-154a-4fa3-a37f-8684c6a74954.jpg</url>
      <title>Forem: CVERiskPilot</title>
      <link>https://forem.com/cveriskpilot</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://forem.com/feed/cveriskpilot"/>
    <language>en</language>
    <item>
      <title>[Boost]</title>
      <dc:creator>CVERiskPilot</dc:creator>
      <pubDate>Tue, 31 Mar 2026 02:52:04 +0000</pubDate>
      <link>https://forem.com/cveriskpilot/-28m3</link>
      <guid>https://forem.com/cveriskpilot/-28m3</guid>
      <description>&lt;div class="ltag__link--embedded"&gt;
  &lt;div class="crayons-story "&gt;
  &lt;a href="https://dev.to/cveriskpilot/i-built-a-free-compliance-scanner-because-the-enterprise-ones-cost-more-than-my-rent-2c11" class="crayons-story__hidden-navigation-link"&gt;I built a free compliance scanner because the enterprise ones cost more than my rent&lt;/a&gt;


  &lt;div class="crayons-story__body crayons-story__body-full_post"&gt;
    &lt;div class="crayons-story__top"&gt;
      &lt;div class="crayons-story__meta"&gt;
        &lt;div class="crayons-story__author-pic"&gt;

          &lt;a href="/cveriskpilot" class="crayons-avatar  crayons-avatar--l  "&gt;
            &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3849832%2F1f9793e2-154a-4fa3-a37f-8684c6a74954.jpg" alt="cveriskpilot profile" class="crayons-avatar__image" width="325" height="325"&gt;
          &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
          &lt;div&gt;
            &lt;a href="/cveriskpilot" class="crayons-story__secondary fw-medium m:hidden"&gt;
              CVERiskPilot
            &lt;/a&gt;
            &lt;div class="profile-preview-card relative mb-4 s:mb-0 fw-medium hidden m:inline-block"&gt;
              
                CVERiskPilot
                
              
              &lt;div id="story-author-preview-content-3433328" class="profile-preview-card__content crayons-dropdown branded-7 p-4 pt-0"&gt;
                &lt;div class="gap-4 grid"&gt;
                  &lt;div class="-mt-4"&gt;
                    &lt;a href="/cveriskpilot" class="flex"&gt;
                      &lt;span class="crayons-avatar crayons-avatar--xl mr-2 shrink-0"&gt;
                        &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3849832%2F1f9793e2-154a-4fa3-a37f-8684c6a74954.jpg" class="crayons-avatar__image" alt="" width="325" height="325"&gt;
                      &lt;/span&gt;
                      &lt;span class="crayons-link crayons-subtitle-2 mt-5"&gt;CVERiskPilot&lt;/span&gt;
                    &lt;/a&gt;
                  &lt;/div&gt;
                  &lt;div class="print-hidden"&gt;
                    
                      Follow
                    
                  &lt;/div&gt;
                  &lt;div class="author-preview-metadata-container"&gt;&lt;/div&gt;
                &lt;/div&gt;
              &lt;/div&gt;
            &lt;/div&gt;

          &lt;/div&gt;
          &lt;a href="https://dev.to/cveriskpilot/i-built-a-free-compliance-scanner-because-the-enterprise-ones-cost-more-than-my-rent-2c11" class="crayons-story__tertiary fs-xs"&gt;&lt;time&gt;Mar 31&lt;/time&gt;&lt;span class="time-ago-indicator-initial-placeholder"&gt;&lt;/span&gt;&lt;/a&gt;
        &lt;/div&gt;
      &lt;/div&gt;

    &lt;/div&gt;

    &lt;div class="crayons-story__indention"&gt;
      &lt;h2 class="crayons-story__title crayons-story__title-full_post"&gt;
        &lt;a href="https://dev.to/cveriskpilot/i-built-a-free-compliance-scanner-because-the-enterprise-ones-cost-more-than-my-rent-2c11" id="article-link-3433328"&gt;
          I built a free compliance scanner because the enterprise ones cost more than my rent
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;div class="crayons-story__tags"&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/security"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;security&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/opensource"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;opensource&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/devops"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;devops&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/beginners"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;beginners&lt;/a&gt;
        &lt;/div&gt;
      &lt;div class="crayons-story__bottom"&gt;
        &lt;div class="crayons-story__details"&gt;
          &lt;a href="https://dev.to/cveriskpilot/i-built-a-free-compliance-scanner-because-the-enterprise-ones-cost-more-than-my-rent-2c11" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left"&gt;
            &lt;div class="multiple_reactions_aggregate"&gt;
              &lt;span class="multiple_reactions_icons_container"&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/sparkle-heart-5f9bee3767e18deb1bb725290cb151c25234768a0e9a2bd39370c382d02920cf.svg" width="24" height="24"&gt;
                  &lt;/span&gt;
              &lt;/span&gt;
              &lt;span class="aggregate_reactions_counter"&gt;1&lt;span class="hidden s:inline"&gt; reaction&lt;/span&gt;&lt;/span&gt;
            &lt;/div&gt;
          &lt;/a&gt;
            &lt;a href="https://dev.to/cveriskpilot/i-built-a-free-compliance-scanner-because-the-enterprise-ones-cost-more-than-my-rent-2c11#comments" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left flex items-center"&gt;
              Comments


              &lt;span class="hidden s:inline"&gt;Add Comment&lt;/span&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div class="crayons-story__save"&gt;
          &lt;small class="crayons-story__tertiary fs-xs mr-2"&gt;
            2 min read
          &lt;/small&gt;
            
              &lt;span class="bm-initial"&gt;
                

              &lt;/span&gt;
              &lt;span class="bm-success"&gt;
                

              &lt;/span&gt;
            
        &lt;/div&gt;
      &lt;/div&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;


</description>
      <category>security</category>
      <category>opensource</category>
      <category>devops</category>
      <category>beginners</category>
    </item>
    <item>
      <title>I built a free compliance scanner because the enterprise ones cost more than my rent</title>
      <dc:creator>CVERiskPilot</dc:creator>
      <pubDate>Tue, 31 Mar 2026 01:43:26 +0000</pubDate>
      <link>https://forem.com/cveriskpilot/i-built-a-free-compliance-scanner-because-the-enterprise-ones-cost-more-than-my-rent-2c11</link>
      <guid>https://forem.com/cveriskpilot/i-built-a-free-compliance-scanner-because-the-enterprise-ones-cost-more-than-my-rent-2c11</guid>
      <description>&lt;p&gt;I'm a cybersecurity engineer — 7 years in, currently a Security Policy Analyst, previously an Application Security Architect. I started building a SaaS product on the side and immediately hit a wall: how do I prove this thing is compliant without spending $50k on GRC tooling?&lt;/p&gt;

&lt;p&gt;So I built the compliance mapping myself. Then I realized it was more useful than the SaaS it was meant to protect.&lt;/p&gt;

&lt;h2&gt;
  
  
  The problem
&lt;/h2&gt;

&lt;p&gt;You run &lt;code&gt;npm audit&lt;/code&gt;. You get 47 vulnerabilities. Now what?&lt;/p&gt;

&lt;p&gt;Which ones violate SOC 2 controls? Which ones show up on a CMMC assessment? Which ones would a FedRAMP auditor flag? Nobody tells you that. You're supposed to figure it out by cross-referencing CVEs to CWEs to NIST controls to framework mappings — manually, in spreadsheets, on a Friday afternoon.&lt;/p&gt;

&lt;p&gt;That's insane.&lt;/p&gt;

&lt;h2&gt;
  
  
  What I built
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;npx @cveriskpilot/scan@latest &lt;span class="nt"&gt;--preset&lt;/span&gt; startup
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;


&lt;p&gt;One command. No account. No API key. Runs offline.&lt;/p&gt;

&lt;p&gt;It scans your dependencies, secrets, and IaC configs, then maps every finding to &lt;strong&gt;6 compliance frameworks&lt;/strong&gt;: NIST 800-53, SOC 2, CMMC, FedRAMP, OWASP ASVS, and SSDF.&lt;/p&gt;

&lt;p&gt;Instead of just "lodash has CVE-2021-23337," you get:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;The CWE classification&lt;/li&gt;
&lt;li&gt;Which NIST 800-53 controls it violates&lt;/li&gt;
&lt;li&gt;The SOC 2, CMMC, and FedRAMP impact&lt;/li&gt;
&lt;li&gt;A severity-based verdict (true positive, false positive, needs review)&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;All in your terminal. JSON, SARIF, and Markdown output if you need it for CI/CD or reports.&lt;/p&gt;
&lt;h2&gt;
  
  
  Why I'm posting this
&lt;/h2&gt;

&lt;p&gt;I've been building in a vacuum. The scanner works, it's on npm, but I haven't gotten much feedback from the people who would actually use it.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;A few things I'd genuinely love input on:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Is the terminal output too dense, or do you want all that detail?&lt;/li&gt;
&lt;li&gt;What package managers should I support next? (Currently: npm, yarn, pnpm, Go, pip)&lt;/li&gt;
&lt;li&gt;Would you actually use a GitHub Action wrapper for this?&lt;/li&gt;
&lt;li&gt;Does compliance mapping even matter to you, or is that only a concern when a prospect asks?&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;
  
  
  Try it
&lt;/h2&gt;


&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="c"&gt;# scan current directory with startup preset&lt;/span&gt;
npx @cveriskpilot/scan@latest &lt;span class="nt"&gt;--preset&lt;/span&gt; startup

&lt;span class="c"&gt;# just dependencies&lt;/span&gt;
npx @cveriskpilot/scan@latest &lt;span class="nt"&gt;--scan&lt;/span&gt; deps

&lt;span class="c"&gt;# output as JSON&lt;/span&gt;
npx @cveriskpilot/scan@latest &lt;span class="nt"&gt;--preset&lt;/span&gt; startup &lt;span class="nt"&gt;--format&lt;/span&gt; json &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; results.json
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;


&lt;p&gt;Zero dependencies. Works on Node 20+. Takes about 30 seconds.&lt;/p&gt;


&lt;div class="crayons-card c-embed text-styles text-styles--secondary"&gt;
    &lt;div class="c-embed__content"&gt;
      &lt;div class="c-embed__body flex items-center justify-between"&gt;
        &lt;a href="https://www.npmjs.com/package/@cveriskpilot/scan" rel="noopener noreferrer" class="c-link fw-bold flex items-center"&gt;
          &lt;span class="mr-2"&gt;npmjs.com&lt;/span&gt;
          

        &lt;/a&gt;
      &lt;/div&gt;
    &lt;/div&gt;
&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;GitHub:&lt;/strong&gt; &lt;a href="https://github.com/devbrewster/cveriskpilot-scan" rel="noopener noreferrer"&gt;devbrewster/cveriskpilot-scan&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;I'm a solo veteran founder building this bootstrapped from Texas. If this is useful to even one person who would've otherwise spent a weekend in spreadsheet hell — that's a win.&lt;/p&gt;

&lt;p&gt;Tear it apart. I can take it.&lt;/p&gt;

</description>
      <category>security</category>
      <category>opensource</category>
      <category>devops</category>
      <category>beginners</category>
    </item>
  </channel>
</rss>
