deptrust
Multi-ecosystem package vulnerability checker
TLDR
SYNOPSIS
deptrust command [ecosystem] [package] [version]
DESCRIPTION
deptrust is a Go CLI that checks package versions for known vulnerabilities across npm, PyPI, crates.io, Go modules, RubyGems, NuGet, Maven, Packagist, pub.dev, CocoaPods, Hex.pm, Hackage, and GitHub Actions. It queries OSV and the GitHub Advisory Database directly — no hosted deptrust service required.Each check returns a recommendation: block (critical/high), review (medium/unknown or recent publish), or allow (no blocking vulnerabilities found). allow does not prove a package is safe. JSON output includes advisory coverage, risk score, vulnerability details, and provider errors.Also runs as a local MCP server and integrates with Codex and Claude Code via install hooks that vet package commands before they execute.
PARAMETERS
check
Query known vulnerabilities for a package version.suggest
Return the newest version with an allow recommendation.compare
Compare risk between two versions of the same package.version
Show the installed deptrust version.mcp
Start the MCP server for agent integrations.--json
Emit structured JSON output.
CAVEATS
Provider coverage varies by ecosystem; partial or missing coverage returns unknown, which should not be treated as safe. GitHub Actions branch refs and major-only tags add review signals even when technically valid.
SEE ALSO
npm-audit(1), osv-scanner(1), snyk(1)
