dsh-dep-vuln-scan avatar

dsh-dep-vuln-scan

Scan project lockfiles (npm/pnpm/yarn/pip/go/cargo/maven/gradle) against the free OSV API and report confirmed dependency vulnerabilities with fix versions

PluginSecurityNetworkVision / OCR
Verification
L2 · Structured
Security
Low
Health
Active
Trust
Silver

What it does

Scan project lockfiles (npm/pnpm/yarn/pip/go/cargo/maven/gradle) against the free OSV API and report confirmed dependency vulnerabilities with fix versions

Installation

dsh plugin --profile web add github:988hj7tczd-oss/dsh-dep-vuln-scan

Install method: GitHub · no verification record (L1-L5)

Compatibility

DSH VersionStatus
not statedno verification record

Requirements

  • • Node.js: not stated
  • • DSH: not stated
  • • External credentials: none detected

Security Report

Automated static scan, not manual review.

DSH.SO VETPASSEDda05cd
Automated review · daily
PASSED

Vet static analysis found no suspicious behavior — verdict is clean.

0 critical·0 high·1 medium·94 score
plugin version0.1.0dsh manifest
scanned commitda05cd83da0b2026-08-24
latest commitda05cd83da0b
vet verdictclean · npmscore 94

Vet is an AST static scan (npm artifact or git source).

Disclaimer: automated static analysis, not a security guarantee. Always review what you install.

Risk details

No critical or warning findings.

Activity

Last commit 2026-08-24 · activity: Active

• Repo created: 2026-08-24

• Stars: ★ 0 · Forks: 0

• Health: Active — committed within last 30 days

Source

GitHub: github.com/988hj7tczd-oss/dsh-dep-vuln-scan

Was this page helpful?