pkgscan
Scan requirements.txt, package.json, and Cargo.toml for outdated packages and known CVEs — no API keys required.
Uses OSV for vulnerability data and PyPI/npm/crates.io for latest version checks.
Install
pip install pkgscan
Usage
# Scan a single file
pkgscan requirements.txt
# Auto-discover all dependency files under a directory
pkgscan --dir .
# Skip CVE checks (faster)
pkgscan requirements.txt --skip-vulns
# Only show outdated packages
pkgscan --dir . --only-outdated
# Only show packages with known CVEs
pkgscan --dir . --only-vulns
Example output
requirements.txt (12 packages)
────────────────────────────────────────────────────────────────────────
requests 2.28.0 → 2.31.0 [CVE-2023-32681]
flask 2.2.5 → 3.0.0
click 8.1.3 8.1.7 ✓ up to date
Summary: 2 outdated, 1 vulnerable
Exit code is 0 when all packages are up-to-date and vulnerability-free, 1 otherwise — handy for CI.
Supported files
| File | Ecosystem |
|---|---|
requirements.txt / requirements-*.txt |
PyPI |
pyproject.toml |
PyPI |
package.json |
npm |
Cargo.toml |
crates.io |
CI integration
- name: Scan dependencies
run: pkgscan --dir . --skip-vulns
License
MIT
Metadata
Release files for pkgscan 0.2.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| pkgscan-0.2.0.tar.gz | 9.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| pkgscan-0.2.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 17.6 kB
Release files / pkgscan-0.2.0.tar.gz
| Download URL | pkgscan-0.2.0.tar.gz |
|---|---|
| Size | 9.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
0978443a3d5ccc13f97b394b13781cf7fc1d0d1f23b97c5fac312c438152d150
|
|
BLAKE2b-256 checksum How to use checksums |
b197204512a971dabb0dafd2fa3841086982ac4cbdb82974b7d2e4b27544d12d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.13.12
|
Release files / pkgscan-0.2.0-py3-none-any.whl
| Download URL | pkgscan-0.2.0-py3-none-any.whl |
|---|---|
| Size | 7.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
6a329a1baaa981d5c3c369f3305de0e72e44ec3ac596e5334b5f524db1f1bcc0
|
|
BLAKE2b-256 checksum How to use checksums |
6f610eb24f9f249c870967b87f00666dc1e935342a5c1513db456650be73f0f6
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.13.12
|