AI Agent Hub
Back to skills
Dependency Scanner icon

Dependency Scanner

IT Ops & Security Updated 2026.08.29

Paste the following prompt into your AI chat to install this skill:

Please follow https://skillhub.cn/install/skillhub.md and install @user_8509461a/dependency-scanner.

About this skill

Problem it solves

Multi-language projects pull in many third-party packages quickly. Files such as package.json, requirements.txt, pom.xml, and go.mod may contain known CVEs, copyleft licenses, or outdated versions. Relying only on npm audit or manual review gives limited coverage, so teams need a repeatable security baseline for local checks, CI/CD, and release gates.

How it works

dependency-scanner targets Node.js/npm, Python/pip, Java/Maven, Go, PHP, Ruby, .NET, and Rust ecosystems. It reads dependency manifests and lockfiles such as package-lock.json, Pipfile.lock, and go.sum, then checks them against CVE/NVD, GitHub Advisory, OSV, Snyk, and language-specific databases. The workflow includes:
- Vulnerability detection: classifies findings as Critical, High, Medium, or Low, with CVSS scores and patched versions.
- License compliance: flags GPL/AGPL or other licenses that may conflict with the project.
- Outdated dependency review: reports old versions, latest releases, and potential Breaking Changes.
- Remediation guidance: proposes upgrades and can support automated PRs in CI/CD.

Use it for routine audits, pre-release checks, and security incident response. Scan results still require human review for business impact; validate upgrades in test environments and record a clear reason when ignoring a CVE.

Use Cases

  • Run Node.js dependency CVE checks in CI and block releases when Critical findings occur.
  • Scan Python requirements.txt and Pipfile.lock before service release to report vulnerabilities and patched versions.
  • Review Java pom.xml dependency licenses before upgrades to identify GPL compatibility risks.
  • Check Go module CVEs and available upgraded versions during security incident response.

Best For

  • Node.js backend security engineers: quickly locate CVEs, license issues, and outdated dependencies before merges.
  • Python data service engineers: confirm requirements.txt and lockfiles have no high-risk vulnerabilities before release.
  • SREs managing Java microservice builds: use dependency security scanning as a CI release gate.
  • Platform engineers responsible for multi-language repository compliance: assess risks across package.json, go.mod, and pom.xml.