Skip to content

Releases: LouayeG/deprot

v1.0.0

Choose a tag to compare

@LouayeG LouayeG released this 14 Sep 22:40

The first stable release. deprot is a local-first, keyless CLI that grades every dependency A→F for rot & supply-chain risk — no API keys, no cloud, no signup.

Stability: the deprot command line — its flags, exit codes, and --json / --sarif / --sbom output shapes — is the stable, semver-governed surface from 1.0 onward.

✨ New in 1.0

  • PyPI from source — requirements.txt and pyproject.toml (PEP 621 and Poetry) are now parsed, so a Python project is graded straight from source, not only from an installed environment.
  • Grade badge (--badge) — emit an embeddable SVG for your project's overall grade, or a shields.io endpoint JSON with --json. Drop it in your README.
  • Typosquat radar across all 8 ecosystems — bundled popular-name lists added for Ruby, PHP, Maven and NuGet.

🔧 Fixes & quality

  • Fairer scoring — a maturity dampener stops a widely-used, complete library that simply hasn't shipped lately from being graded as "rotting" on staleness alone. It only ever lifts a score; deprecation, an archived repo, and unresolved high/critical advisories still force RISKY.
  • Honest reachability — --reach now reports an explicit unscanned verdict for ecosystems without a source-import scanner, instead of implying those dependencies were checked.
  • Accurate minimum Rust version (1.90) — cargo install no longer fails confusingly on older toolchains. CI now builds on a pinned MSRV toolchain and dogfoods deprot against its own repository.
  • Added a per-ecosystem capability matrix to the README, plus CHANGELOG, SECURITY, CONTRIBUTING, issue/PR templates, and end-to-end CLI tests.

Install

cargo install deprot

Requires Rust 1.90+. Prebuilt binaries for Linux, macOS and Windows are attached to this release.

Full changelog: v0.7.0...v1.0.0

v0.7.0

Choose a tag to compare

@github-actions github-actions released this 14 Sep 08:18

Three new capabilities: parser-backed malware detection, four more ecosystems, and a runtime network monitor.

☣️ AST-aware malware scanning (--malware)

The malicious-code scanner now parses JavaScript, TypeScript, and Python with tree-sitter and confirms dropper patterns structurally instead of by line-regex:

  • obfuscated-eval — eval/Function/exec/compile on a decoded (atob, Buffer.from, base64.b64decode, …) or string-concatenated payload, caught even when spread across newlines or comments.
  • dynamic-code-exec — an exec sink invoked on the return value of a function call.
  • Far fewer false positives — the pattern appearing inside a string literal or comment is no longer flagged.
  • Every finding is tagged AST (parser-confirmed) or regex (heuristic) in the table, JSON, and SARIF.

📦 Eight ecosystems for vulnerability & risk scanning

Added Ruby (RubyGems), PHP (Packagist), Maven, and NuGet alongside npm, crates.io, PyPI, and Go:

  • New manifest parsers: Gemfile, composer.json, pom.xml, *.csproj / packages.config.
  • New lockfile parsers with exact versions and blast-radius edges: composer.lock, Gemfile.lock.
  • PHP vulnerabilities are sourced directly from OSV (Packagist isn't indexed by deps.dev), so --vulns works there too — flagging every known CVE for a pinned Composer package with CVSS and the fixed version.

📡 Runtime network monitoring (--watch)

deprot --watch -- npm install

Runs a command and reports every outbound connection its process tree makes, in real time, from /proc — no root, no packet capture, no extra dependencies. A postinstall that phones home, a cloud-metadata credential probe (169.254.169.254), or any connection to a public host stands out immediately; loopback and LAN traffic are ignored. Includes a table, --json output, and a CI gate (non-zero exit on a metadata/external connection). Linux.

Notes

  • No API keys, no cloud, no signup — as always.
  • --watch is Linux-only for now (macOS support is on the roadmap).

Install: cargo install deprot

Full changelog: v0.6.0...v0.7.0

v0.6.0 — hygiene, reachability & malware scanning

Choose a tag to compare

@LouayeG LouayeG released this 14 Sep 01:20

Three new static security capabilities — keyless, local, dependency-light.

🧰 --hygiene — repository security posture, graded 0–100

A local mini-Scorecard (no GitHub API): security policy, a committed lockfile per ecosystem, a .gitignore that actually covers secrets, no committed credential files (tracked-only via git ls-files, .example templates allowed), automated dependency updates (Dependabot/Renovate), CI, and CODEOWNERS — severity-weighted into a letter grade with per-gap remediation. --json.

🎯 --reach — dependency reachability (find unused deps)

Scans source imports and classifies each dependency used (with the file it's imported in) / unused (a runtime dep never imported — a removal candidate and needless attack surface) / dev. Finer than a runtime-vs-build split. npm / Cargo / Go. --json.

☣️ --malware — malicious-code / dropper signatures

Scans source for the specific signatures of supply-chain malware, tuned for low false positives: obfuscated eval (running a base64/hex decode), reverse shells (/dev/tcp, nc -e, bash -i), curl | sh, cloud-metadata (IMDS) credential probes (169.254.169.254), credential-file access (~/.aws/credentials, SSH keys, .npmrc, browser stores), heavy obfuscation, and shell-history tampering. --json / per-line --sarif; fails CI on a high/critical hit.

New crates: deprot-hygiene, deprot-reach, deprot-malware.

Install

```
cargo install deprot
```
Prebuilt Linux / macOS (arm64 + x64) / Windows binaries attached below.

v0.5.0 — GitHub Actions workflow security

Choose a tag to compare

@LouayeG LouayeG released this 13 Sep 23:44

Third security capability, closing another gap — still keyless, still local.

⚙️ --workflows — lock down your CI

Audits .github/workflows for the current GitHub Actions supply-chain attacks, worst-first, with exact line numbers:

  • template-injection — untrusted ${{ github.event.* }} / github.head_ref interpolated into a run: shell step (the classic Actions RCE).
  • pwn-request — pull_request_target / workflow_run that checks out attacker-controlled PR code (ref: …head.sha) with secrets in scope (Critical).
  • unpinned-action / mutable-ref-action — a uses: not pinned to a full commit SHA; @main/@master is worst. First-party vs third-party is severity-weighted.
  • broad-permissions / missing-permissions — write-all, or no explicit least-privilege block.
  • dangerous-trigger and curl-pipe-shell.

--json for CI and --sarif for per-line GitHub code-scanning alerts; exits non-zero on any finding. Backed by a new pure, line-oriented analyzer (deprot-actions) — no YAML dependency, exact locations.

Install

```
cargo install deprot
```
Prebuilt Linux / macOS (arm64 + x64) / Windows binaries attached below.

v0.4.0 — vuln-first CVE audit + secret scanning

Choose a tag to compare

@LouayeG LouayeG released this 13 Sep 23:01

Two capabilities that move deprot ahead of pure security scanners on their own turf — still keyless, still local.

🛡️ --vulns — OSV-backed, vuln-first, per-CVE

A dedicated vulnerability audit: every known advisory affecting your packages, worst-first — CVE id, CVSS, and the exact fixed version to upgrade to. Vulnerability data is OSV.dev merged with GitHub/deps.dev advisories (a strict superset of either source), with CVSS computed from the raw v3.0/3.1 vector. Scans the resolved lockfile tree (transitive coverage) or the manifest.

  • --vulns --json for CI, --vulns --sarif for per-CVE GitHub code-scanning alerts (with security-severity), exits non-zero on any finding.

🔑 --secrets — catch leaked credentials before they ship

Scans your own source for hardcoded API keys, tokens, and private keys: high-precision format rules (AWS, GitHub/GitLab, Slack, Stripe, Google, OpenAI/Anthropic, npm/PyPI, SendGrid, Twilio, PEM keys, JWT) plus Shannon-entropy detection for unknown formats.

  • Aggressive false-positive suppression (placeholders, ${ENV} refs, doc/example keys, node_modules/build dirs, binaries, lockfiles).
  • Output is always redacted; inline deprot:allow-secret suppresses a line.
  • --json and --sarif (per-line file locations); exits non-zero on any finding.

Install

```
cargo install deprot
```
Prebuilt Linux / macOS (arm64 + x64) / Windows binaries attached below.

v0.3.0 — multi-package / monorepo discovery

Choose a tag to compare

@LouayeG LouayeG released this 13 Sep 20:18

The headline of this release: deprot now understands multi-package repos. Point it at a repo root and it finds and grades every subproject — no more empty-root dead ends.

🗂️ Multi-package / monorepo discovery — --recursive

One repo, many subprojects: a frontend/ (package.json), a backend/ (go.mod), packages/* (Cargo.toml)… deprot --recursive <dir> discovers every manifest under the directory (skipping node_modules, vendor, target, …), grades each in its own section, and fails CI on the worst verdict across all of them. Combined multi-package JSON via --json.

When you run plain deprot on such a repo and the root manifest is empty, deprot now hints you toward --recursive instead of reporting "no dependencies".

🐹 Go support

A go.mod parser (single-line + block require, // indirect → transitive) and a new Go ecosystem wired through scoring, the typosquat radar, CycloneDX purls (pkg:golang/…), the TUI, and --fix (go get). Backed by deps.dev's go system — still no API keys.

📦 Also in this release — --installed

Grade the packages actually on disk at their exact installed versions — node_modules, the active Python environment (importlib.metadata, deprot's first Python support), and with --global the global npm root + pipx. Catches drift from the lockfile and hand-installed packages.

Install

```
cargo install deprot
```
Prebuilt Linux / macOS (arm64 + x64) / Windows binaries are attached below.

v0.2.0

Choose a tag to compare

@LouayeG LouayeG released this 13 Sep 06:08

Bug-fix release focused on correctness of the risk verdict.

Fixes

  • core — unresolved packages no longer grade as healthy. A dependency the collector couldn't resolve (unknown/typosquatted name, registry 404, or a failed/offline lookup) used to still earn the "no known advisories" credit and average into a reassuring ~B/Caution, so --fail-on risky never caught it. These are now forced RISKY with an explicit "no registry data" reason.
  • manifest — npm lockfileVersion: 1 is rejected with an actionable error instead of silently reporting "no dependencies". Empty v2/v3 lockfiles remain valid.
  • collect — cache keys are non-lossy. Distinct npm packages that sanitized to the same string (@scope/pkg, scope-pkg, scope.pkg) shared a cache file and could be served each other's facts; keys now include a stable FNV-1a hash of the raw name.
  • tui — the detail pane resets and re-animates when a filter or query moves the selection to a different package.

Install

cargo install deprot

Prebuilt binaries for Linux, macOS (arm64/x64) and Windows are attached below.

deprot v0.1.0 — first release 🦀🧟

Choose a tag to compare

@LouayeG LouayeG released this 12 Sep 23:48

deprot grades your dependencies for rot & supply-chain risk — local-first, no API keys, no cloud, no signup.

cargo install deprot

Highlights

  • 🎓 Report-card scoring — every dependency gets a 0–100 score, a letter grade (A→F), and an OK/CAUTION/RISKY verdict, with --explain for the reasons.
  • 🖥️ Interactive TUI (--tui) — project-health gauge, grade-distribution chart, big letter grades, animated signal bars.
  • 🌳 Whole-tree analysis (--tree) — scores every transitive dependency at its exact locked version, with blast radius + highest-leverage fix.
  • 🧬 Supply-chain deep dive (--deep) — maintainer capture-risk (the xz-style concentration check) + install-script detection.
  • 🩹 Remediation solver (--tree --fix) — the exact upgrades that raise your grades.
  • 🕵️ Typosquat detection, 🔀 PR diff (--diff), ⏳ release history (--history).
  • 📜 Policy-as-code (.deprot.toml) with time-boxed waivers.
  • 🔌 SARIF + CycloneDX SBOM export, and a fully ✈️ air-gapped mode (--offline).

Data

Everything comes from free, public, keyless sources (deps.dev, OSV, the registries). Your code never leaves your machine.

Install

cargo install deprot, or grab a prebuilt binary from the assets below.

Dual-licensed MIT / Apache-2.0. Made by LouayeG.