/** * JavaScript library, framework, and build-tool detection patterns with * version extraction and known CVE mappings. * * Used for client-side technology fingerprinting: identifies libraries from * script URLs, global variables, DOM attributes, meta tags, and HTML comments. * When a version can be extracted, it is cross-referenced against known CVEs * to surface vulnerable dependencies. * * References: * - https://cve.mitre.org/ * - https://www.npmjs.com/advisories * - https://snyk.io/vuln/ */ /** A client-side technology detection profile. */ export interface TechPattern { /** Library / framework / tool name */ name: string; /** Classification */ category: "library" | "framework" | "build-tool" | "runtime"; /** Detection heuristics — at least one field must match */ detection: { /** Regex patterns matched against