# carrot-scan を npm でインストール

carrot-scan のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。

## インストール

```sh
sudo av install npm:carrot-scan
```

追加のインストールコマンド:

### ポータブルおよび言語マネージャ

- npm (100%):

```sh
npm install -g carrot-scan
```

  証拠: local npm package metadata

## パッケージ情報

- **パッケージキー:** npm:carrot-scan
- **パッケージマネージャ:** npm
- **パッケージマネージャページ:** <https://www.npmjs.com/package/carrot-scan>
- **バージョン:** 6.0.1
- **ソース概要:** Command-line tool for detecting vulnerabilities in files and directories.
- **ホームページ:** <https://github.com/SonoTommy/carrot-scan#readme>
- **リポジトリ:** <https://github.com/SonoTommy/carrot-scan>
- **上流ドキュメント:** <https://github.com/SonoTommy/carrot-scan#readme>
- **ライセンス:** MIT
- **ソースアーカイブ:** <https://registry.npmjs.org/carrot-scan/-/carrot-scan-6.0.1.tgz>
- **課題トラッカー:** <https://github.com/SonoTommy/carrot-scan/issues>
- **公開日:** 2025-07-07T09:58:52.520Z
- **最終更新:** 2025-07-07T09:58:52.520Z
- **生成日時:** 2026-08-04T22:13:35+00:00

## 実行可能ファイル

- carrot-scan (cli)
- carrot-scan (エイリアス)

## 依存関係

- @carrot-scan/core
- @fastify/swagger
- @fastify/swagger-ui
- chalk
- commander
- fastify
- figlet
- inquirer
- open
- open-cli
- yaml

## ビルド依存関係

- @eslint/js
- eslint
- eslint-config-prettier
- eslint-plugin-import
- eslint-plugin-prettier
- eslint-plugin-security
- eslint-plugin-unicorn
- execa
- globals
- jest
- jest-cli
- js-x-ray
- prettier
- semgrep

## インストール挙動

- post-install フック: 定義済み
- npm ライフサイクルスクリプト: postinstall
- Bottle: 利用不可

## バージョンと鮮度

- ページ生成日: 2026-08-04
- マネージャ版: 6.0.1
- マネージャ更新日: 2025-07-07
- ローカルデータ: OK
- 上流リポジトリ: https://github.com/SonoTommy/carrot-scan
- 警告: The package-manager record has not been updated in over a year.
- 情報: No cached GitHub release or tag data was available.

## セキュリティノート

carrot-scan に一致するローカルシークレット処理マニフェストは見つかりませんでした。将来の対応で安定したパッケージ URL を使えるよう、パッケージメタデータはここに公開されています。


## ソースデータベース詳細

- **Source Database:** npm registry
- **Dist Tags:** Canary: 6.0.4-canary.4, Latest: 6.0.1
- **Version Count:** 27,708
- **Maintainers:** justsouichi
- **Author:** SonoTommy [https://github.com/SonoTommy]
- **Publisher:** justsouichi
- **Funding:** <https://ko-fi.com/sonotommy>
- **Integrity:** sha512-y2sdPDCpOD5YJ87Qm81hrwHn8vTckMQGcvPvdQ+hLuhoB+VAdOVj54KFQQhZmkMUbYaAAeRdnLcSAb4gKGn+Iw==
- **Shasum:** 9c8b4efb64534d439c28d7f13a8a8637cd6c4a31
- **Unpacked Size:** 202,448
- **File Count:** 0
- **Created At:** 2025-06-23T20:17:40.124Z
- **Latest Published At:** 2025-07-07T09:58:52.520Z
- **Modified At:** 2025-07-07T11:22:49.790Z


## 関連リンク

- [Security and crypto packages](https://pkg.so/ja/security-crypto-tools/) - Matched curated package taxonomy and local package facts.
- [auditjs](https://pkg.so/ja/npm/auditjs/) - Both packages work with overlapping file formats or content types. Shared terms: api, chalk, cli, figlet, scan.
- [yarn-audit-fix](https://pkg.so/ja/npm/yarn-audit-fix/) - Both packages work with overlapping file formats or content types. Shared terms: chalk, cli, commander, fast, scanning.
- [retire](https://pkg.so/ja/npm/retire/) - Security-sensitive metadata or terminology overlaps. Shared terms: analysis, cli, commander, detecting, scanning.

## ソース

- pkg.so package database
- package-page enrichment
- package version freshness
- pkgdb category and tag curation
- package relationship graph
- cross-ecosystem install command graph
