The philosophy of DSH (DeepSeek Harness) is “everything is a plugin.” When building agents or managing project dependencies, checking lock files for vulnerabilities is a common need. dsh-dep-vuln-scan is a native tool that eliminates the need to manually query the OSV API or run npm audit / pip-audit locally, and is directly integrated into the DSH workflow.

This is a native dependency vulnerability scanning tool for DSH (DeepSeek Harness). It reads project lock files within the workspace, queries vulnerabilities in bulk via the free OSV interface (api.osv.dev, no key required), and outputs a table and summary including package name, current version, vulnerability ID (CVE/GHSA), summary, CVSS, and fixed version. The fix command is persisted to tool/result via presentationMeta, supporting replay and copy. This tool is maintained by 988hj7tczd-oss and is licensed under the MIT License.

Core Features

  • Ecosystem Support: Covers npm, PyPI, Go, crates.io, Maven, NuGet, RubyGems.
  • Data Source: Uses OSV’s POST /v1/querybatch interface, which is free and requires no API key.
  • Verification Criteria: Only confirmed existing vulnerabilities are displayed, confirmed through version-filtered OSV queries and local range verification (introduced ≤ version < fixed).
  • Fix Information: Uses the earliest fixed version among the affected ranges and generates suggested fix commands.
  • Severity: Displays CVSSv3 numerical scores (Critical/High/Medium/Low); when no numerical score is available, it uses OSV’s qualitative keywords.
  • Scan Modes: Supports fast (default, root lock files only, concurrency 4) and full (recursively scans subdirectories, concurrency 16, and generates an SBOM summary).
  • Robustness: Uses chunked queries (250 per batch), concurrency pool, 30s timeout, 2 retries, and 429 error handling.
  • Persistence: Projects the report into tool/result.meta via presentationMeta.

Installation and Enablement

Install it into the profile as a DSH plugin bundle:

dsh plugin --profile demo add ./dsh-dep-vuln-scan

After installation, the model can invoke the tool directly.

Typical Usage

The tool interface is defined as follows:

dep_vuln_scan(path?: string, ecosystems?: string[], effort?: 'fast'|'full')
  • path: Project directory or path to a single lock file. If omitted, scan lock files at the workspace root.
  • ecosystems: Filter package types, such as ['npm', 'pypi'].
  • effort: Defaults to fast; full mode recursively discovers dependencies and generates an SBOM summary.

Implementation Details

This plugin module complies with the Cordis specification. Core files include index.ts (assembly and system prompt registration), tools/dep-scan.ts (tool definition and orchestration), lockfile-parsers.ts (lock file parsing), osv-client.ts (network requests and retry logic), and report.ts (report assembly and persistence).

Limitations and Notes

  • Parsing Limitations: pnpm-lock.yaml and yarn.lock use line-level parsing and skip peer suffixes and Yarn Berry special markers; requirements.txt only supports exact == version queries; pom.xml/gradle only recognizes literal versions and ignores ${property} placeholders.
  • Scan Limits: Recursive depth is limited to 8, and a single project is limited to 200 lock files.
  • Permissions: This tool performs read-only operations and does not modify project files. Fix commands are only displayed as suggestions and must be confirmed and executed by the user.

License

MIT

Source: https://github.com/988hj7tczd-oss/dsh-dep-vuln-scan