SARTHAK2511/dsh-cve-audit
Live CVE/supply-chain audit for your workspace's own dependencies (npm/pip/go), backed by OSV.dev. A DeepSeek Harness (dsh) Cordis plugin.
Listed
0
Security
Bundle verified
Preview
What it does
Live CVE/supply-chain audit for your workspace's own project dependencies (npm/pip/go), backed by OSV.dev, with a `cve_audit` tool plus optional automatic re-scan on lockfile changes.
Best for
- npm, Python, or Go projects that need known-vulnerability checks against their own dependency files.
- Agents that need an on-demand `cve_audit` tool backed by OSV.dev.
- Workspaces that benefit from automatic rescanning when supported lockfiles change.
Not ideal for
- Auditing DSH plugins themselves; its stated scope is the workspace project's dependencies.
- Offline environments that cannot query the configured OSV endpoint.
- Production-critical auditing that requires a live-DSH-validated implementation; the project describes itself as an early, not-yet-live-tested scaffold.
README
dsh-cve-audit
Live CVE / supply-chain audit for your project’s own dependencies — not the harness’s plugins.
Most existing dsh security plugins (dsh-plugin-vetting, dsh-plugin-sentinel, upstream-radar) audit the plugin ecosystem itself. None of them scan the dependency lockfiles of the codebase you’re actually working in. dsh-cve-audit fills that gap: it reads package-lock.json / requirements.txt / go.sum in the workspace, batch-queries OSV.dev (free, no API key), and reports known CVEs sorted by severity — as a real tool the agent can call, and optionally re-run automatically whenever a lockfile changes.
Install
dsh plugin add @dsh-plugins/dsh-cve-audit
Usage
Ask the agent to “audit dependencies for CVEs” — it will call the cve_audit tool. Or trigger it directly:
cve_audit({ path: "." })
Config
watch: true # re-scan automatically on lockfile changes
ecosystems: [npm, PyPI, Go]
osvEndpoint: https://api.osv.dev/v1/querybatch
Status
Early scaffold — built against the publicly documented Cordis plugin API (ctx.tools.register, defineTool, Schema.object, ctx.effect). Not yet run against a live dsh install; the lockfile watch currently uses Node’s fs.watch rather than a harness-native workspace-change event, since that event name isn’t in the public docs yet — swap in the native hook once confirmed. PRs welcome.
Frequently Asked QuestionsFAQ
Use the verified command dsh plugin --profile default add github:SARTHAK2511/dsh-cve-audit in a DSH-enabled shell. The command resolves the public package metadata and keeps the plugin attached to the catalog identity shown on this page.
Compatibility follows the bundle and profile status shown above. If a profile is not detected, keep the plugin disabled there and check the repository documentation before enabling it in production.
The GitHub link and activity metadata are the source of truth for releases and maintenance. Revisit this page after a new release to confirm the catalog has observed the latest version.