Verification
L2 · Structured
Security
Low
Health
Active
Trust
Silver
What it does
Scan project lockfiles (npm/pnpm/yarn/pip/go/cargo/maven/gradle) against the free OSV API and report confirmed dependency vulnerabilities with fix versions
Installation
dsh plugin --profile web add github:988hj7tczd-oss/dsh-dep-vuln-scanInstall method: GitHub · no verification record (L1-L5)
Compatibility
| DSH Version | Status |
|---|---|
| not stated | no verification record |
Requirements
- • Node.js: not stated
- • DSH: not stated
- • External credentials: none detected
Security Report
Automated static scan, not manual review.
DSH.SO VETPASSEDda05cd
Security reviewAutomated review · daily
PASSED
Vet static analysis found no suspicious behavior — verdict is clean.
0 critical·0 high·1 medium·94 score
plugin version
0.1.0dsh manifestscanned commit
da05cd83da0b2026-08-24latest commit
da05cd83da0bvet verdict
clean · npmscore 94Vet is an AST static scan (npm artifact or git source).
`[](https://www.dsh.so/artifact/dsh-dep-vuln-scan/)`Disclaimer: automated static analysis, not a security guarantee. Always review what you install.
Risk details
No critical or warning findings.
Activity
Last commit 2026-08-24 · activity: Active
• Repo created: 2026-08-24
• Stars: ★ 0 · Forks: 0
• Health: Active — committed within last 30 days
