vamp-supply-chain
Overview
vamp-supply-chain is a supply chain security scanner that audits project dependencies for CVE vulnerabilities, typosquatting attacks, and checksum integrity. It automatically detects dependency manifests (requirements.txt, pyproject.toml, setup.cfg, package.json) and queries OSV.dev for known vulnerabilities, performs Levenshtein-distance typosquatting detection against a curated list of 30 popular packages, and verifies package checksums against PyPI metadata. It can also generate Software Bill of Materials (SBOM) in CycloneDX JSON format. Findings are rated CRITICAL to INFO and exported to Console (Rich), JSON, or HTML.
Features
- Automatic dependency manifest discovery:
requirements.txt,requirements-*.txt,pyproject.toml([project].dependencies),setup.cfg([options].install_requires),package.json(dependencies+devDependencies) - CVE check via OSV.dev API: POST to
https://api.osv.dev/v1/queryper package with severity rated CRITICAL/HIGH from CVSS score - Typosquatting detection: pure-Python Levenshtein distance (no external library) against 30 curated popular packages; distance ≤ 2 triggers HIGH severity finding
- Checksum verification: queries
https://pypi.org/pypi/{pkg}/{version}/jsonand compares.tar.gzSHA-256; unresolved packages flagged as MEDIUM - SBOM generation (subcommand
sbom): CycloneDX JSON withbomFormat,specVersion,serialNumber, per-componentpurl(pkg:pypi/name@version) andlicenses - Rich console output: per-issue-type panels and a severity summary table
- Export to JSON and HTML (standalone, dark-theme)
- Exit codes for CI/CD pipeline integration
Requirements
- Python 3.9 or later
rich >= 13.7.0aiohttp >= 3.8.0
Installation
pip install vamp-supply-chain
# o con Homebrew:
brew install vampsecure-labs/labs/vamp-supply-chain
git clone https://github.com/Vampsecure-Labs/vamp-supply-chain.git
cd vamp-supply-chain
python3 -m venv .venv
source .venv/bin/activate # Windows: .venv\Scripts\activate
pip install -r requirements.txt
Usage
vamp-supply-chain --help
usage: vamp-supply-chain [-h] {scan,sbom} ...
vamp-supply-chain — Supply Chain Security Scanner (VampSecure Labs)
subcommands:
scan Scan dependency manifests for CVEs, typosquatting and checksum issues
sbom Generate a CycloneDX SBOM from discovered dependencies
Examples
# Scan all dependency manifests in the current directory
vamp-supply-chain scan --path .
# Scan a specific project and export findings to JSON and HTML
vamp-supply-chain scan --path /path/to/project --json results.json --html report.html
# Scan and also emit a CycloneDX SBOM
vamp-supply-chain scan --path . --sbom sbom.json
# Generate SBOM only (no vulnerability check)
vamp-supply-chain sbom --path . --output sbom.json
# Generate SBOM in SPDX format
vamp-supply-chain sbom --path . --output sbom.json --format spdx
CLI Reference
scan
| Flag | Default | Description |
|---|---|---|
--path DIR |
. |
Directory to scan for dependency manifests |
--json FILE |
— | Export findings to JSON |
--html FILE |
— | Export dark-theme HTML report |
--sbom FILE |
— | Also emit a CycloneDX SBOM alongside the scan |
sbom
| Flag | Default | Description |
|---|---|---|
--path DIR |
. |
Directory to scan for dependency manifests |
--output FILE |
sbom.json |
Output SBOM file path |
--format FORMAT |
cyclonedx |
SBOM format: cyclonedx or spdx |
Output Formats
| Format | Flag | Description |
|---|---|---|
| Console | (default) | Rich panels grouped by issue type with severity color-coding |
| JSON | --json FILE |
Machine-readable full finding set |
| HTML | --html FILE |
Dark-theme standalone report |
| SBOM | --sbom FILE / sbom --output |
CycloneDX JSON Software Bill of Materials |
Exit Codes
| Code | Meaning | CI/CD Behavior |
|---|---|---|
0 |
No CRITICAL or HIGH findings | Pipeline passes |
1 |
CRITICAL or HIGH findings detected | Pipeline fails — review required |
2 |
Execution error | Pipeline fails — check configuration |
Legal Notice
Use exclusively on systems you own or for which you hold explicit written authorization from the system owner. VampSecure Studios assumes no liability for unauthorized use.
Part of VampSecure Labs Toolkit
vamp-supply-chain is one tool in the VampSecure Labs security research toolkit. For the full toolkit including the orchestrator that runs all tools in sequence and aggregates findings into a single engagement report, see:
- Portfolio: github.com/Vampsecure-Labs
- Orchestrator: github.com/Vampsecure-Labs/vamp-orchestrator
© VampSecure Studios — VampSecure Labs Security Research Division
Versión
v1.0 — VampSecure Labs Security Research Division
Metadata
Release files for vamp-supply-chain 1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| vamp_supply_chain-1.0.tar.gz | 24.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| vamp_supply_chain-1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 51.0 kB
Release files / vamp_supply_chain-1.0.tar.gz
| Download URL | vamp_supply_chain-1.0.tar.gz |
|---|---|
| Size | 24.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
d2ef9184d89e0b91d16f78a7b6e903a7877ff1da3e4ebb45bd2b6d6b088acd37
|
|
BLAKE2b-256 checksum How to use checksums |
d576f866d512c83f2a61585ec8f1bc541b82552718e050b8c72278ce319f6647
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.6
|
Release files / vamp_supply_chain-1.0-py3-none-any.whl
| Download URL | vamp_supply_chain-1.0-py3-none-any.whl |
|---|---|
| Size | 26.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
eb7f443d4e3f0a0f7b061bc97f7773c1b2dabd1ee811f0a0df590039f15be9f5
|
|
BLAKE2b-256 checksum How to use checksums |
5577f3a3461287f37a1295af97407e02601a166d7b119bde40df88c48bdcdbe9
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.6
|