Organization data from Github https://github.com/RetireJS
What you require you must also retire
GitHub:@RetireJS
scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.
Grunt plugin for retire.