Skip to content

Vulnerability scanning

depsmith-docs-bot[bot] edited this page Oct 1, 2026 · 2 revisions

Vulnerability scanning

Scanning is opt-in and uses Grype (installed separately).

depsmith scan  --root PATH --target pixi:pixi.toml --fail-on high --json
depsmith check --root PATH --target pixi:pixi.toml --scan --fail-on high --only-new --json

scan checks the current lock; --scan on check/update scans the baseline and the candidate with one vulnerability database snapshot per target. A scanner failure blocks that target's proposal (exit 3).

Reports

Each scan report lists every candidate finding. With a baseline lock (comparison = "baseline") findings are classified as introduced, resolved or remaining. Without one the report is candidate-only: nothing is claimed as introduced or resolved, and --only-new assesses all findings because "new" cannot be established. Each finding records its artifact and applicability: upstream, or unknown build/backport status for conda packages matched through an upstream identity.

Identities and coverage

Packages are scanned only under an identity that can be verified:

  • public PyPI artifacts from files.pythonhosted.org;
  • crates from crates.io;
  • GitHub actions at an exact release tag;
  • reviewed identity mappings:
[[options.identity_mappings]]
ecosystem = "conda"
name = "urllib3"
purl = "pkg:pypi/urllib3"
evidence = "https://…"   # reviewed provenance; not verified by depsmith

Conda names are never assumed to be PyPI names. Unmapped packages, local packages, Git references, floating or SHA-pinned action references (a version comment is not evidence) and unknown versions are unassessed: reported, never treated as clean. A passing policy therefore does not imply complete coverage.

Policy and suppressions

--fail-on SEVERITY rejects the proposal (exit 4) for findings at or above negligible, low, medium, high or critical; --only-new limits it to introduced findings.

Suppressions name the advisory, a documented reason and a scope (a package as ecosystem:name, a target, or both), with an optional last day it applies. Suppressed findings stay in reports and are only excluded from the policy; expired suppressions are listed and not applied.

[[options.suppressions]]
id = "GHSA-v845-jxx5-vc9f"
package = "pypi:urllib3"
reason = "No cross-origin redirects with cookies in our usage"
expires = "2026-12-31"

Clone this wiki locally