Reading the results
Dependencies
The resolved dependency tree across the portfolio, with known advisories matched against it.
Across eight ecosystems
Dependencies are collected from repository scans across eight package ecosystems, including the operating-system packages a container image installs. The advisory match runs against the resolved tree rather than the manifest, so a vulnerable version that arrived transitively is still found.

Phantom dependencies
A package the code imports but the manifest never declares will not appear in any lockfile audit, because as far as the lockfile is concerned it does not exist. It is reported separately for that reason.
SBOM export
The tree can be exported as an SBOM, from the interface or from the CLI.
node webcuris.cjs sbom