dsh-cve-audit

by SARTHAK2511

工具与能力github 检测到 manifest package.json#dsh 社区精选 收录于 08-17

工作区自身项目依赖(npm/pip/go)的实时 CVE 与供应链审计:OSV.dev 支撑的 cve_audit 工具,lockfile 变更时可自动重扫

Live CVE/supply-chain audit for your workspace's own project dependencies (npm/pip/go), backed by OSV.dev, with a `cve_audit` tool plus optional automatic re-scan on lockfile changes.

安装

dsh plugin --profile web add github:SARTHAK2511/dsh-cve-audit

GitHub 源码安装:首次需按提示配置 allowBuilds 构建授权后重试

安装与环境配置指引、插件开发教程见 DSH 中文社区文档 ↗

安装即在你的机器上以你的权限运行第三方代码——它可读写文件、使用凭据、访问网络,DSH 的工具审批不会为插件代码加沙箱。「检测到 manifest」仅代表发现 dsh.bundle / dsh.plugin 清单,不构成兼容性或安全审查;安装前请审阅源码,不熟悉的插件先在不含密钥的环境试用。

README

目录

Live CVE / supply-chain audit for your project's own dependencies — not the harness's plugins.

Most existing dsh security plugins (dsh-plugin-vetting, dsh-plugin-sentinel, upstream-radar) audit the plugin ecosystem itself. None of them scan the dependency lockfiles of the codebase you're actually working in. dsh-cve-audit fills that gap: it reads package-lock.json / requirements.txt / go.sum in the workspace, batch-queries OSV.dev (free, no API key), and reports known CVEs sorted by severity — as a real tool the agent can call, and optionally re-run automatically whenever a lockfile changes.

Install

dsh plugin add @dsh-plugins/dsh-cve-audit

Usage

Ask the agent to "audit dependencies for CVEs" — it will call the cve_audit tool. Or trigger it directly:

cve_audit({ path: "." })

Config

watch: true          # re-scan automatically on lockfile changes
ecosystems: [npm, PyPI, Go]
osvEndpoint: https://api.osv.dev/v1/querybatch

Status

Early scaffold — built against the publicly documented Cordis plugin API (ctx.tools.register, defineTool, Schema.object, ctx.effect). Not yet run against a live dsh install; the lockfile watch currently uses Node's fs.watch rather than a harness-native workspace-change event, since that event name isn't in the public docs yet — swap in the native hook once confirmed. PRs welcome.

原始 README: https://github.com/SARTHAK2511/dsh-cve-audit/blob/main/README.md ↗