If you've got a Maven project containing JavaScript dependencies (usually some legacy Java web application), you can run vulnerability scan against it.
The script is based on https://retirejs.github.io/retire.js/
Run in main folder, where src/
is located.