Skip to main content

Supply Chain Scanner

Local-first vulnerability scanner for project dependencies, developer tools, and IDE extensions.
Uses multi-source intelligence (OSV, NVD, GHSA, Sonatype) with KEV/EPSS prioritization.

No API key required for default usage.

Public repo: https://github.com/DevInder1/supply-chain-scanner-public


Install (plug and play)

Python (recommended)

pip install devinder-supply-chain-scanner
supply-chain-scanner --scan all --project-path . --output-dir scanner-output

npm (Node wrapper)

Requires Python 3.10+ and the pip package above.

npm install -g @devinder1/supply-chain-scanner-cli
supply-chain-scanner --scan project --project-path .

Use in your own Python app

from scanner import run_scan

summary = run_scan(
    project_path=".",
    scan="all",
    run_profile="full",  # no API key required
    output_dir="scanner-output",
)
print(summary["summary"])

Scan profiles

Profile Description
full (default) Project + system + extensions. OSV + NVD without keys.
quick Faster project-focused scan.
offline Local advisory DB only, no network.
Power-user Add GITHUB_TOKEN, NVD_API_KEY, optional SONATYPE_TOKEN for best coverage.

Desktop app

cd apps/desktop
npm install
npm run start

Development

git clone https://github.com/DevInder1/supply-chain-scanner-public.git
cd supply-chain-scanner-public
python3 -m pip install -e .
supply-chain-scanner --help
python3 -m unittest scanner.tests.test_matcher_ranges -v

CLI contract: docs/cli-contract.md
Publishing: docs/PUBLISHING.md


Optional API keys (power users)

Variable Purpose
NVD_API_KEY Higher NVD rate limits
GITHUB_TOKEN GHSA advisories
SONATYPE_TOKEN Sonatype Guide advisories

Set in .env or environment variables.


License

MIT — see LICENSE

Metadata

Release files for devinder-supply-chain-scanner 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Built distribution (wheel)

Table of built distributions (wheels) for devinder-supply-chain-scanner 0.1.0
File Interpreter ABI Platform
devinder_supply_chain_scanner-0.1.0-py3-none-any.whl Python 3 none any Details

Release files / devinder_supply_chain_scanner-0.1.0-py3-none-any.whl

Download URL devinder_supply_chain_scanner-0.1.0-py3-none-any.whl
Size 92.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
4d501895b5768285033e08ad2d1faae901505dc0a9bf92525f642b2765a22bf4
BLAKE2b-256 checksum
How to use checksums
015450dcae58983b2c41db0d10bfd51553f759e1de982784b5e27dc57dc53382
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.11.7

Release history Release notifications | RSS feed

This release

0.1.0 This release

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page