SARTHAK2511/dsh-cve-audit

Live CVE/supply-chain audit for your workspace's own dependencies (npm/pip/go), backed by OSV.dev. A DeepSeek Harness (dsh) Cordis plugin.

Bundle verified Unknown TypeScript Unknown
Bundle verified

Listed

0

Security

Bundle verified

VersionUnknown
LanguageTypeScript
LicenseUnknown
View on GitHub

Preview

Preview 1 of 2: SARTHAK2511/dsh-cve-audit
Preview 2 of 2: SARTHAK2511/dsh-cve-audit

What it does

Live CVE/supply-chain audit for your workspace's own project dependencies (npm/pip/go), backed by OSV.dev, with a `cve_audit` tool plus optional automatic re-scan on lockfile changes.

Best for

  • npm, Python, or Go projects that need known-vulnerability checks against their own dependency files.
  • Agents that need an on-demand `cve_audit` tool backed by OSV.dev.
  • Workspaces that benefit from automatic rescanning when supported lockfiles change.

Not ideal for

  • Auditing DSH plugins themselves; its stated scope is the workspace project's dependencies.
  • Offline environments that cannot query the configured OSV endpoint.
  • Production-critical auditing that requires a live-DSH-validated implementation; the project describes itself as an early, not-yet-live-tested scaffold.

README

dsh-cve-audit

Live CVE / supply-chain audit for your project’s own dependencies — not the harness’s plugins.

Most existing dsh security plugins (dsh-plugin-vetting, dsh-plugin-sentinel, upstream-radar) audit the plugin ecosystem itself. None of them scan the dependency lockfiles of the codebase you’re actually working in. dsh-cve-audit fills that gap: it reads package-lock.json / requirements.txt / go.sum in the workspace, batch-queries OSV.dev (free, no API key), and reports known CVEs sorted by severity — as a real tool the agent can call, and optionally re-run automatically whenever a lockfile changes.

Install

dsh plugin add @dsh-plugins/dsh-cve-audit

Usage

Ask the agent to “audit dependencies for CVEs” — it will call the cve_audit tool. Or trigger it directly:

cve_audit({ path: "." })

Config

watch: true          # re-scan automatically on lockfile changes
ecosystems: [npm, PyPI, Go]
osvEndpoint: https://api.osv.dev/v1/querybatch

Status

Early scaffold — built against the publicly documented Cordis plugin API (ctx.tools.register, defineTool, Schema.object, ctx.effect). Not yet run against a live dsh install; the lockfile watch currently uses Node’s fs.watch rather than a harness-native workspace-change event, since that event name isn’t in the public docs yet — swap in the native hook once confirmed. PRs welcome.

Frequently Asked QuestionsFAQ

Use the verified command dsh plugin --profile default add github:SARTHAK2511/dsh-cve-audit in a DSH-enabled shell. The command resolves the public package metadata and keeps the plugin attached to the catalog identity shown on this page.