# Elm packages audit tool

**URL:** <https://discourse.elm-lang.org/t/elm-packages-audit-tool/2125>\
**Category:** Request Feedback\
**Created:** [October 4, 2018, 7:32am UTC](https://discourse.elm-lang.org/t/elm-packages-audit-tool/2125 "2018-10-04T07:32:27Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jirisliva](https://yyz1.discourse-cdn.com/flex035/user_avatar/discourse.elm-lang.org/jirisliva/32/1366_2.png) [@jirisliva](https://discourse.elm-lang.org/u/jirisliva)\
**Post date:** [October 4, 2018, 7:32am UTC](https://discourse.elm-lang.org/t/elm-packages-audit-tool/2125/1 "2018-10-04T07:32:27Z")

</div>

Do you know any tool to audit third-party package?  
Some think like `npm audit`(or Soatype in Java world).

Tool which check third-party dependencies (Elm packagse) and say if they are out-of-date or have _known issues_.

---

<div class="post-metadata">

**Author:** ![Janiczek](https://yyz1.discourse-cdn.com/flex035/user_avatar/discourse.elm-lang.org/janiczek/32/4516_2.png) [@Janiczek](https://discourse.elm-lang.org/u/Janiczek)\
**Post date:** [October 4, 2018, 10:50am UTC](https://discourse.elm-lang.org/t/elm-packages-audit-tool/2125/2 "2018-10-04T10:50:29Z")

</div>

I believe it would be possible to have [a tool that checks third-party dependencies](https://www.npmjs.com/package/elm-outdated) for **out-of-date versions** , but I don’t know what would **known issues** mean in Elm ecosystem.

ie. what would be the Elm equivalent of [https://www.npmjs.com/advisories](https://www.npmjs.com/advisories) ? Is it even possible to have security vulnerabilities in published Elm packages? Or do you mean **bugs etc.** by known issues?

---

<div class="post-metadata">

**Author:** ![jirisliva](https://yyz1.discourse-cdn.com/flex035/user_avatar/discourse.elm-lang.org/jirisliva/32/1366_2.png) [@jirisliva](https://discourse.elm-lang.org/u/jirisliva)\
**Post date:** [October 9, 2018, 6:45am UTC](https://discourse.elm-lang.org/t/elm-packages-audit-tool/2125/3 "2018-10-09T06:45:30Z")

</div>

Yes typical _know issues_ in nodejs packages are not possible in Elm world but still there can be some issues in implementation which leads to recommendation to not use it (like Arrays in Elm 0.18).

Thanks for elm-outdated. I missed that.

---

<div class="post-metadata">

**Author:** ![mfeineis](https://yyz1.discourse-cdn.com/flex035/user_avatar/discourse.elm-lang.org/mfeineis/32/104_2.png) [@mfeineis](https://discourse.elm-lang.org/u/mfeineis)\
**Post date:** [October 10, 2018, 4:37pm UTC](https://discourse.elm-lang.org/t/elm-packages-audit-tool/2125/4 "2018-10-10T16:37:25Z")

</div>

I like the idea but less for the package content itself and more for checking compatible licenses (whatever that means, is probably context dependent and is not legally binding…) and such 🙂

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex035/uploads/elm_lang/original/1X/50a05e53677a2c3b47776d7abd0f113eb50193a1.png) [@system](https://discourse.elm-lang.org/u/system)\
**Post date:** [October 20, 2018, 4:37pm UTC](https://discourse.elm-lang.org/t/elm-packages-audit-tool/2125/5 "2018-10-20T16:37:28Z")

</div>

This topic was automatically closed 10 days after the last reply. New replies are no longer allowed.
