Supply Chain Scanner
Local-first vulnerability scanner for project dependencies, developer tools, and IDE extensions.
Uses multi-source intelligence (OSV, NVD, GHSA, Sonatype) with KEV/EPSS prioritization.
No API key required for default usage.
Public repo: https://github.com/DevInder1/supply-chain-scanner-public
Install (plug and play)
Python (recommended)
pip install devinder-supply-chain-scanner
supply-chain-scanner --scan all --project-path . --output-dir scanner-output
npm (Node wrapper)
Requires Python 3.10+ and the pip package above.
npm install -g @devinder1/supply-chain-scanner-cli
supply-chain-scanner --scan project --project-path .
Use in your own Python app
from scanner import run_scan
summary = run_scan(
project_path=".",
scan="all",
run_profile="full", # no API key required
output_dir="scanner-output",
)
print(summary["summary"])
Scan profiles
| Profile | Description |
|---|---|
full (default) |
Project + system + extensions. OSV + NVD without keys. |
quick |
Faster project-focused scan. |
offline |
Local advisory DB only, no network. |
| Power-user | Add GITHUB_TOKEN, NVD_API_KEY, optional SONATYPE_TOKEN for best coverage. |
Desktop app
cd apps/desktop
npm install
npm run start
Development
git clone https://github.com/DevInder1/supply-chain-scanner-public.git
cd supply-chain-scanner-public
python3 -m pip install -e .
supply-chain-scanner --help
python3 -m unittest scanner.tests.test_matcher_ranges -v
CLI contract: docs/cli-contract.md
Publishing: docs/PUBLISHING.md
Optional API keys (power users)
| Variable | Purpose |
|---|---|
NVD_API_KEY |
Higher NVD rate limits |
GITHUB_TOKEN |
GHSA advisories |
SONATYPE_TOKEN |
Sonatype Guide advisories |
Set in .env or environment variables.
License
MIT — see LICENSE
Metadata
Release files for devinder-supply-chain-scanner 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| devinder_supply_chain_scanner-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Release files / devinder_supply_chain_scanner-0.1.0-py3-none-any.whl
| Download URL | devinder_supply_chain_scanner-0.1.0-py3-none-any.whl |
|---|---|
| Size | 92.1 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
4d501895b5768285033e08ad2d1faae901505dc0a9bf92525f642b2765a22bf4
|
|
BLAKE2b-256 checksum How to use checksums |
015450dcae58983b2c41db0d10bfd51553f759e1de982784b5e27dc57dc53382
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.11.7
|