- Startseite
- Plugins
- Sicherheit & Berechtigungen
- dsh-cve-audit
dsh-cve-audit
sarthak2511/dsh-cve-audit
Live-CVE-/Supply-Chain-Audit für die Projektabhängigkeiten deines Arbeitsbereichs (npm/pip/go), gestützt auf OSV.dev, mit einem cve_audit-Werkzeug und optionalem automatischem Neuscan bei Lockfile-Änderungen.
Installation
dsh plugin --profile web add github:sarthak2511/dsh-cve-auditREADME
dsh-cve-audit
Live CVE / supply-chain audit for your project's own dependencies — not the harness's plugins.
Most existing dsh security plugins (dsh-plugin-vetting, dsh-plugin-sentinel, upstream-radar) audit the plugin ecosystem itself. None of them scan the dependency lockfiles of the codebase you're actually working in. dsh-cve-audit fills that gap: it reads package-lock.json / requirements.txt / go.sum in the workspace, batch-queries OSV.dev (free, no API key), and reports known CVEs sorted by severity — as a real tool the agent can call, and optionally re-run automatically whenever a lockfile changes.
Install
dsh plugin add @dsh-plugins/dsh-cve-audit
Usage
Ask the agent to "audit dependencies for CVEs" — it will call the cve_audit tool. Or trigger it directly:
cve_audit({ path: "." })
Config
watch: true # re-scan automatically on lockfile changes
ecosystems: [npm, PyPI, Go]
osvEndpoint: https://api.osv.dev/v1/querybatch
Status
Early scaffold — built against the publicly documented Cordis plugin API (ctx.tools.register, defineTool, Schema.object, ctx.effect). Not yet run against a live dsh install; the lockfile watch currently uses Node's fs.watch rather than a harness-native workspace-change event, since that event name isn't in the public docs yet — swap in the native hook once confirmed. PRs welcome.
Ähnliche Plugins
dsh-infinite-gen-4
minglink/dsh-infinite-gen-4
cc-safety-net
kenryu42/cc-safety-net
api-relay-audit
toby-bridges/api-relay-audit
dsh-redteam-model
seaof0/dsh-redteam-model