-
Notifications
You must be signed in to change notification settings - Fork 0
Vulnerability scanning
Scanning is opt-in and uses Grype (installed separately).
depsmith scan --root PATH --target pixi:pixi.toml --fail-on high --json
depsmith check --root PATH --target pixi:pixi.toml --scan --fail-on high --only-new --jsonscan checks the current lock; --scan on check/update scans the
baseline and the candidate with one vulnerability database snapshot per
target. A scanner failure blocks that target's proposal (exit 3).
Each scan report lists every candidate finding. With a baseline lock
(comparison = "baseline") findings are classified as introduced, resolved or
remaining. Without one the report is candidate-only: nothing is claimed as
introduced or resolved, and --only-new assesses all findings because "new"
cannot be established. Each finding records its artifact and applicability:
upstream, or unknown build/backport status for conda packages matched
through an upstream identity.
Packages are scanned only under an identity that can be verified:
- public PyPI artifacts from
files.pythonhosted.org; - crates from crates.io;
- GitHub actions at an exact release tag;
- reviewed identity mappings:
[[options.identity_mappings]]
ecosystem = "conda"
name = "urllib3"
purl = "pkg:pypi/urllib3"
evidence = "https://…" # reviewed provenance; not verified by depsmithConda names are never assumed to be PyPI names. Unmapped packages, local packages, Git references, floating or SHA-pinned action references (a version comment is not evidence) and unknown versions are unassessed: reported, never treated as clean. A passing policy therefore does not imply complete coverage.
--fail-on SEVERITY rejects the proposal (exit 4) for findings at or above
negligible, low, medium, high or critical; --only-new limits it to
introduced findings.
Suppressions name the advisory, a documented reason and a scope (a package
as ecosystem:name, a target, or both), with an optional last day it applies.
Suppressed findings stay in reports and are only excluded from the policy;
expired suppressions are listed and not applied.
[[options.suppressions]]
id = "GHSA-v845-jxx5-vc9f"
package = "pypi:urllib3"
reason = "No cross-origin redirects with cookies in our usage"
expires = "2026-12-31"