node-env-resolve@1.0.9
14 capabilities · 69 targets · 184 capability uses
ReportEvrel shows when package updates gain new capabilities like reading secrets, reaching networks, touching files, running shell commands, or loading dynamic code—with source-linked evidence. We're extending the same review to AI-authored application changes before merge.
3 capability types · 10 targets · 13 occurrences
environment.readruntime.patch.mutatesystem.info.readnode-env-resolve@1.0.9
14 capabilities · 69 targets · 184 capability uses
Reportdotenv@16.4.5
3 capabilities · 8 targets · 8 capability uses
Reportrequest@2.88.2
3 capabilities · 10 targets · 13 capability uses
Reportdrizzle-orm@0.45.2
2 capabilities · 2 targets · 2 capability uses
ReportDiff review was not built for machine-speed changes, behavior introduced deep in dependencies, or generated code that arrives faster than teams can understand it.
See when a change adds access to environment data, files, processes, networks, browser storage, or dynamic code.
Trace each capability use to the exact file and location that introduced it.
Separate added, removed, and unchanged behavior between versions.
Choose which modeled capabilities Evrel should call out in every report.
We're inviting a small number of AppSec and platform security teams to use Evrel on real Node.js and TypeScript changes—and shape the evidence their reviewers need to approve or investigate them.