Skip to main content

vamp-supply-chain

Python 3.9+ Platform License AGPL-3.0 VampSecure Labs

Overview

vamp-supply-chain is a supply chain security scanner that audits project dependencies for CVE vulnerabilities, typosquatting attacks, and checksum integrity. It automatically detects dependency manifests (requirements.txt, pyproject.toml, setup.cfg, package.json) and queries OSV.dev for known vulnerabilities, performs Levenshtein-distance typosquatting detection against a curated list of 30 popular packages, and verifies package checksums against PyPI metadata. It can also generate Software Bill of Materials (SBOM) in CycloneDX JSON format. Findings are rated CRITICAL to INFO and exported to Console (Rich), JSON, or HTML.

Features

  • Automatic dependency manifest discovery: requirements.txt, requirements-*.txt, pyproject.toml ([project].dependencies), setup.cfg ([options].install_requires), package.json (dependencies + devDependencies)
  • CVE check via OSV.dev API: POST to https://api.osv.dev/v1/query per package with severity rated CRITICAL/HIGH from CVSS score
  • Typosquatting detection: pure-Python Levenshtein distance (no external library) against 30 curated popular packages; distance ≤ 2 triggers HIGH severity finding
  • Checksum verification: queries https://pypi.org/pypi/{pkg}/{version}/json and compares .tar.gz SHA-256; unresolved packages flagged as MEDIUM
  • SBOM generation (subcommand sbom): CycloneDX JSON with bomFormat, specVersion, serialNumber, per-component purl (pkg:pypi/name@version) and licenses
  • Rich console output: per-issue-type panels and a severity summary table
  • Export to JSON and HTML (standalone, dark-theme)
  • Exit codes for CI/CD pipeline integration

Requirements

  • Python 3.9 or later
  • rich >= 13.7.0
  • aiohttp >= 3.8.0

Installation

pip install vamp-supply-chain
# o con Homebrew:
brew install vampsecure-labs/labs/vamp-supply-chain
git clone https://github.com/Vampsecure-Labs/vamp-supply-chain.git
cd vamp-supply-chain
python3 -m venv .venv
source .venv/bin/activate   # Windows: .venv\Scripts\activate
pip install -r requirements.txt

Usage

vamp-supply-chain --help
usage: vamp-supply-chain [-h] {scan,sbom} ...

vamp-supply-chain — Supply Chain Security Scanner (VampSecure Labs)

subcommands:
  scan    Scan dependency manifests for CVEs, typosquatting and checksum issues
  sbom    Generate a CycloneDX SBOM from discovered dependencies

Examples

# Scan all dependency manifests in the current directory
vamp-supply-chain scan --path .

# Scan a specific project and export findings to JSON and HTML
vamp-supply-chain scan --path /path/to/project --json results.json --html report.html

# Scan and also emit a CycloneDX SBOM
vamp-supply-chain scan --path . --sbom sbom.json

# Generate SBOM only (no vulnerability check)
vamp-supply-chain sbom --path . --output sbom.json

# Generate SBOM in SPDX format
vamp-supply-chain sbom --path . --output sbom.json --format spdx

CLI Reference

scan

Flag Default Description
--path DIR . Directory to scan for dependency manifests
--json FILE — Export findings to JSON
--html FILE — Export dark-theme HTML report
--sbom FILE — Also emit a CycloneDX SBOM alongside the scan

sbom

Flag Default Description
--path DIR . Directory to scan for dependency manifests
--output FILE sbom.json Output SBOM file path
--format FORMAT cyclonedx SBOM format: cyclonedx or spdx

Output Formats

Format Flag Description
Console (default) Rich panels grouped by issue type with severity color-coding
JSON --json FILE Machine-readable full finding set
HTML --html FILE Dark-theme standalone report
SBOM --sbom FILE / sbom --output CycloneDX JSON Software Bill of Materials

Exit Codes

Code Meaning CI/CD Behavior
0 No CRITICAL or HIGH findings Pipeline passes
1 CRITICAL or HIGH findings detected Pipeline fails — review required
2 Execution error Pipeline fails — check configuration

Use exclusively on systems you own or for which you hold explicit written authorization from the system owner. VampSecure Studios assumes no liability for unauthorized use.

Part of VampSecure Labs Toolkit

vamp-supply-chain is one tool in the VampSecure Labs security research toolkit. For the full toolkit including the orchestrator that runs all tools in sequence and aggregates findings into a single engagement report, see:


© VampSecure Studios — VampSecure Labs Security Research Division

Versión

v1.0 — VampSecure Labs Security Research Division

Metadata

Release files for vamp-supply-chain 1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for vamp-supply-chain 1.0
File Size Uploaded
vamp_supply_chain-1.0.tar.gz 24.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for vamp-supply-chain 1.0
File Interpreter ABI Platform
vamp_supply_chain-1.0-py3-none-any.whl Python 3 none any Details

Total release size: 51.0 kB

Release files / vamp_supply_chain-1.0.tar.gz

Download URL vamp_supply_chain-1.0.tar.gz
Size 24.7 kB
Tags Source
SHA-256 checksum
How to use checksums
d2ef9184d89e0b91d16f78a7b6e903a7877ff1da3e4ebb45bd2b6d6b088acd37
BLAKE2b-256 checksum
How to use checksums
d576f866d512c83f2a61585ec8f1bc541b82552718e050b8c72278ce319f6647
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.6

Release files / vamp_supply_chain-1.0-py3-none-any.whl

Download URL vamp_supply_chain-1.0-py3-none-any.whl
Size 26.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
eb7f443d4e3f0a0f7b061bc97f7773c1b2dabd1ee811f0a0df590039f15be9f5
BLAKE2b-256 checksum
How to use checksums
5577f3a3461287f37a1295af97407e02601a166d7b119bde40df88c48bdcdbe9
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.6

Release history Release notifications | RSS feed

This release

1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page