Repository navigation
Releases: LouayeG/deprot
Release list
v1.0.0
The first stable release. deprot is a local-first, keyless CLI that grades every dependency A→F for rot & supply-chain risk — no API keys, no cloud, no signup.
Stability: the deprot command line — its flags, exit codes, and --json / --sarif / --sbom output shapes — is the stable, semver-governed surface from 1.0 onward.
✨ New in 1.0
- PyPI from source —
requirements.txtandpyproject.toml(PEP 621 and Poetry) are now parsed, so a Python project is graded straight from source, not only from an installed environment. - Grade badge (
--badge) — emit an embeddable SVG for your project's overall grade, or a shields.io endpoint JSON with--json. Drop it in your README. - Typosquat radar across all 8 ecosystems — bundled popular-name lists added for Ruby, PHP, Maven and NuGet.
🔧 Fixes & quality
- Fairer scoring — a maturity dampener stops a widely-used, complete library that simply hasn't shipped lately from being graded as "rotting" on staleness alone. It only ever lifts a score; deprecation, an archived repo, and unresolved high/critical advisories still force RISKY.
- Honest reachability —
--reachnow reports an explicitunscannedverdict for ecosystems without a source-import scanner, instead of implying those dependencies were checked. - Accurate minimum Rust version (1.90) —
cargo installno longer fails confusingly on older toolchains. CI now builds on a pinned MSRV toolchain and dogfoods deprot against its own repository. - Added a per-ecosystem capability matrix to the README, plus
CHANGELOG,SECURITY,CONTRIBUTING, issue/PR templates, and end-to-end CLI tests.
Install
cargo install deprotRequires Rust 1.90+. Prebuilt binaries for Linux, macOS and Windows are attached to this release.
Full changelog: v0.7.0...v1.0.0
v0.7.0
Three new capabilities: parser-backed malware detection, four more ecosystems, and a runtime network monitor.
☣️ AST-aware malware scanning (--malware)
The malicious-code scanner now parses JavaScript, TypeScript, and Python with tree-sitter and confirms dropper patterns structurally instead of by line-regex:
obfuscated-eval—eval/Function/exec/compileon a decoded (atob,Buffer.from,base64.b64decode, …) or string-concatenated payload, caught even when spread across newlines or comments.dynamic-code-exec— an exec sink invoked on the return value of a function call.- Far fewer false positives — the pattern appearing inside a string literal or comment is no longer flagged.
- Every finding is tagged
AST(parser-confirmed) orregex(heuristic) in the table, JSON, and SARIF.
📦 Eight ecosystems for vulnerability & risk scanning
Added Ruby (RubyGems), PHP (Packagist), Maven, and NuGet alongside npm, crates.io, PyPI, and Go:
- New manifest parsers:
Gemfile,composer.json,pom.xml,*.csproj/packages.config. - New lockfile parsers with exact versions and blast-radius edges:
composer.lock,Gemfile.lock. - PHP vulnerabilities are sourced directly from OSV (Packagist isn't indexed by deps.dev), so
--vulnsworks there too — flagging every known CVE for a pinned Composer package with CVSS and the fixed version.
📡 Runtime network monitoring (--watch)
deprot --watch -- npm installRuns a command and reports every outbound connection its process tree makes, in real time, from /proc — no root, no packet capture, no extra dependencies. A postinstall that phones home, a cloud-metadata credential probe (169.254.169.254), or any connection to a public host stands out immediately; loopback and LAN traffic are ignored. Includes a table, --json output, and a CI gate (non-zero exit on a metadata/external connection). Linux.
Notes
- No API keys, no cloud, no signup — as always.
--watchis Linux-only for now (macOS support is on the roadmap).
Install: cargo install deprot
Full changelog: v0.6.0...v0.7.0
v0.6.0 — hygiene, reachability & malware scanning
Three new static security capabilities — keyless, local, dependency-light.
🧰 --hygiene — repository security posture, graded 0–100
A local mini-Scorecard (no GitHub API): security policy, a committed lockfile per ecosystem, a .gitignore that actually covers secrets, no committed credential files (tracked-only via git ls-files, .example templates allowed), automated dependency updates (Dependabot/Renovate), CI, and CODEOWNERS — severity-weighted into a letter grade with per-gap remediation. --json.
🎯 --reach — dependency reachability (find unused deps)
Scans source imports and classifies each dependency used (with the file it's imported in) / unused (a runtime dep never imported — a removal candidate and needless attack surface) / dev. Finer than a runtime-vs-build split. npm / Cargo / Go. --json.
☣️ --malware — malicious-code / dropper signatures
Scans source for the specific signatures of supply-chain malware, tuned for low false positives: obfuscated eval (running a base64/hex decode), reverse shells (/dev/tcp, nc -e, bash -i), curl | sh, cloud-metadata (IMDS) credential probes (169.254.169.254), credential-file access (~/.aws/credentials, SSH keys, .npmrc, browser stores), heavy obfuscation, and shell-history tampering. --json / per-line --sarif; fails CI on a high/critical hit.
New crates: deprot-hygiene, deprot-reach, deprot-malware.
Install
```
cargo install deprot
```
Prebuilt Linux / macOS (arm64 + x64) / Windows binaries attached below.
v0.5.0 — GitHub Actions workflow security
Third security capability, closing another gap — still keyless, still local.
⚙️ --workflows — lock down your CI
Audits .github/workflows for the current GitHub Actions supply-chain attacks, worst-first, with exact line numbers:
template-injection— untrusted${{ github.event.* }}/github.head_refinterpolated into arun:shell step (the classic Actions RCE).pwn-request—pull_request_target/workflow_runthat checks out attacker-controlled PR code (ref: …head.sha) with secrets in scope (Critical).unpinned-action/mutable-ref-action— auses:not pinned to a full commit SHA;@main/@masteris worst. First-party vs third-party is severity-weighted.broad-permissions/missing-permissions—write-all, or no explicit least-privilege block.dangerous-triggerandcurl-pipe-shell.
--json for CI and --sarif for per-line GitHub code-scanning alerts; exits non-zero on any finding. Backed by a new pure, line-oriented analyzer (deprot-actions) — no YAML dependency, exact locations.
Install
```
cargo install deprot
```
Prebuilt Linux / macOS (arm64 + x64) / Windows binaries attached below.
v0.4.0 — vuln-first CVE audit + secret scanning
Two capabilities that move deprot ahead of pure security scanners on their own turf — still keyless, still local.
🛡️ --vulns — OSV-backed, vuln-first, per-CVE
A dedicated vulnerability audit: every known advisory affecting your packages, worst-first — CVE id, CVSS, and the exact fixed version to upgrade to. Vulnerability data is OSV.dev merged with GitHub/deps.dev advisories (a strict superset of either source), with CVSS computed from the raw v3.0/3.1 vector. Scans the resolved lockfile tree (transitive coverage) or the manifest.
--vulns --jsonfor CI,--vulns --sariffor per-CVE GitHub code-scanning alerts (withsecurity-severity), exits non-zero on any finding.
🔑 --secrets — catch leaked credentials before they ship
Scans your own source for hardcoded API keys, tokens, and private keys: high-precision format rules (AWS, GitHub/GitLab, Slack, Stripe, Google, OpenAI/Anthropic, npm/PyPI, SendGrid, Twilio, PEM keys, JWT) plus Shannon-entropy detection for unknown formats.
- Aggressive false-positive suppression (placeholders,
${ENV}refs, doc/example keys,node_modules/build dirs, binaries, lockfiles). - Output is always redacted; inline
deprot:allow-secretsuppresses a line. --jsonand--sarif(per-line file locations); exits non-zero on any finding.
Install
```
cargo install deprot
```
Prebuilt Linux / macOS (arm64 + x64) / Windows binaries attached below.
v0.3.0 — multi-package / monorepo discovery
The headline of this release: deprot now understands multi-package repos. Point it at a repo root and it finds and grades every subproject — no more empty-root dead ends.
🗂️ Multi-package / monorepo discovery — --recursive
One repo, many subprojects: a frontend/ (package.json), a backend/ (go.mod), packages/* (Cargo.toml)… deprot --recursive <dir> discovers every manifest under the directory (skipping node_modules, vendor, target, …), grades each in its own section, and fails CI on the worst verdict across all of them. Combined multi-package JSON via --json.
When you run plain deprot on such a repo and the root manifest is empty, deprot now hints you toward --recursive instead of reporting "no dependencies".
🐹 Go support
A go.mod parser (single-line + block require, // indirect → transitive) and a new Go ecosystem wired through scoring, the typosquat radar, CycloneDX purls (pkg:golang/…), the TUI, and --fix (go get). Backed by deps.dev's go system — still no API keys.
📦 Also in this release — --installed
Grade the packages actually on disk at their exact installed versions — node_modules, the active Python environment (importlib.metadata, deprot's first Python support), and with --global the global npm root + pipx. Catches drift from the lockfile and hand-installed packages.
Install
```
cargo install deprot
```
Prebuilt Linux / macOS (arm64 + x64) / Windows binaries are attached below.
v0.2.0
Bug-fix release focused on correctness of the risk verdict.
Fixes
- core — unresolved packages no longer grade as healthy. A dependency the collector couldn't resolve (unknown/typosquatted name, registry 404, or a failed/offline lookup) used to still earn the "no known advisories" credit and average into a reassuring ~B/Caution, so
--fail-on riskynever caught it. These are now forced RISKY with an explicit "no registry data" reason. - manifest — npm
lockfileVersion: 1is rejected with an actionable error instead of silently reporting "no dependencies". Empty v2/v3 lockfiles remain valid. - collect — cache keys are non-lossy. Distinct npm packages that sanitized to the same string (
@scope/pkg,scope-pkg,scope.pkg) shared a cache file and could be served each other's facts; keys now include a stable FNV-1a hash of the raw name. - tui — the detail pane resets and re-animates when a filter or query moves the selection to a different package.
Install
cargo install deprot
Prebuilt binaries for Linux, macOS (arm64/x64) and Windows are attached below.
deprot v0.1.0 — first release 🦀🧟
deprot grades your dependencies for rot & supply-chain risk — local-first, no API keys, no cloud, no signup.
cargo install deprotHighlights
- 🎓 Report-card scoring — every dependency gets a 0–100 score, a letter grade (A→F), and an OK/CAUTION/RISKY verdict, with
--explainfor the reasons. - 🖥️ Interactive TUI (
--tui) — project-health gauge, grade-distribution chart, big letter grades, animated signal bars. - 🌳 Whole-tree analysis (
--tree) — scores every transitive dependency at its exact locked version, with blast radius + highest-leverage fix. - 🧬 Supply-chain deep dive (
--deep) — maintainer capture-risk (the xz-style concentration check) + install-script detection. - 🩹 Remediation solver (
--tree --fix) — the exact upgrades that raise your grades. - 🕵️ Typosquat detection, 🔀 PR diff (
--diff), ⏳ release history (--history). - 📜 Policy-as-code (
.deprot.toml) with time-boxed waivers. - 🔌 SARIF + CycloneDX SBOM export, and a fully
✈️ air-gapped mode (--offline).
Data
Everything comes from free, public, keyless sources (deps.dev, OSV, the registries). Your code never leaves your machine.
Install
cargo install deprot, or grab a prebuilt binary from the assets below.
Dual-licensed MIT / Apache-2.0. Made by LouayeG.