LinuxCommandLibrary
GitHubF-DroidGoogle Play Store

deptrust

Multi-ecosystem package vulnerability checker

TLDR

Check a specific package version
$ deptrust check npm lodash 4.17.20
copy
Check the latest version
$ deptrust check pypi requests latest
copy
Output results as JSON
$ deptrust check --json cargo serde latest
copy
Suggest the safest available version
$ deptrust suggest npm lodash
copy
Compare two versions
$ deptrust compare npm lodash 4.17.20 4.17.21
copy

SYNOPSIS

deptrust command [ecosystem] [package] [version]

DESCRIPTION

deptrust is a Go CLI that checks package versions for known vulnerabilities across npm, PyPI, crates.io, Go modules, RubyGems, NuGet, Maven, Packagist, pub.dev, CocoaPods, Hex.pm, Hackage, and GitHub Actions. It queries OSV and the GitHub Advisory Database directly — no hosted deptrust service required.Each check returns a recommendation: block (critical/high), review (medium/unknown or recent publish), or allow (no blocking vulnerabilities found). allow does not prove a package is safe. JSON output includes advisory coverage, risk score, vulnerability details, and provider errors.Also runs as a local MCP server and integrates with Codex and Claude Code via install hooks that vet package commands before they execute.

PARAMETERS

check

Query known vulnerabilities for a package version.
suggest
Return the newest version with an allow recommendation.
compare
Compare risk between two versions of the same package.
version
Show the installed deptrust version.
mcp
Start the MCP server for agent integrations.
--json
Emit structured JSON output.

CAVEATS

Provider coverage varies by ecosystem; partial or missing coverage returns unknown, which should not be treated as safe. GitHub Actions branch refs and major-only tags add review signals even when technically valid.

SEE ALSO

RESOURCES

Copied to clipboard
Kai