Dependency Scanner
Paste the following prompt into your AI chat to install this skill:
Please follow https://skillhub.cn/install/skillhub.md and install @user_8509461a/dependency-scanner.
About this skill
Problem it solves
Multi-language projects pull in many third-party packages quickly. Files such as package.json, requirements.txt, pom.xml, and go.mod may contain known CVEs, copyleft licenses, or outdated versions. Relying only on npm audit or manual review gives limited coverage, so teams need a repeatable security baseline for local checks, CI/CD, and release gates.
How it works
dependency-scanner targets Node.js/npm, Python/pip, Java/Maven, Go, PHP, Ruby, .NET, and Rust ecosystems. It reads dependency manifests and lockfiles such as package-lock.json, Pipfile.lock, and go.sum, then checks them against CVE/NVD, GitHub Advisory, OSV, Snyk, and language-specific databases. The workflow includes:
- Vulnerability detection: classifies findings as Critical, High, Medium, or Low, with CVSS scores and patched versions.
- License compliance: flags GPL/AGPL or other licenses that may conflict with the project.
- Outdated dependency review: reports old versions, latest releases, and potential Breaking Changes.
- Remediation guidance: proposes upgrades and can support automated PRs in CI/CD.
Use it for routine audits, pre-release checks, and security incident response. Scan results still require human review for business impact; validate upgrades in test environments and record a clear reason when ignoring a CVE.
Use Cases
- Run Node.js dependency CVE checks in CI and block releases when Critical findings occur.
- Scan Python requirements.txt and Pipfile.lock before service release to report vulnerabilities and patched versions.
- Review Java pom.xml dependency licenses before upgrades to identify GPL compatibility risks.
- Check Go module CVEs and available upgraded versions during security incident response.
Best For
- Node.js backend security engineers: quickly locate CVEs, license issues, and outdated dependencies before merges.
- Python data service engineers: confirm requirements.txt and lockfiles have no high-risk vulnerabilities before release.
- SREs managing Java microservice builds: use dependency security scanning as a CI release gate.
- Platform engineers responsible for multi-language repository compliance: assess risks across package.json, go.mod, and pom.xml.
Related Skills
A lightweight wrapper and automation tool for Jaeger-related GitHub scenarios.
Vault Wrap is a wrapping skill for Vault and GitHub automation.
Port management, threat-intel audits, drift checks, and multi-node monitoring for self-hosted infrastructure.
Provides health checks for HTTP, TCP, Ping, and log sources with dynamic-threshold alerts, anomaly detection, and scheduled inspection reports.