ericrihm/depfence

AI-aware dependency security scanner — CVE, behavioral, supply chain, EPSS, CISA KEV, and MCP scanning

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
pathPath to scan (default: current directory)no.
fail-onMinimum severity to fail the check (critical, high, medium, low, any, none)nohigh
formatOutput format (table, json, sarif)nosarif
scannersComma-separated scanners to skip (no-advisory, no-behavioral, no-reputation)no""
upload-sarifUpload SARIF to GitHub Code Scanning (requires security-events: write)notrue
enrich-epssEnrich findings with EPSS exploit probability scoresnotrue
enrich-kevFlag CISA Known Exploited Vulnerabilitiesnotrue
sbomGenerate CycloneDX SBOM alongside scan resultsnofalse
python-versionPython version to useno3.12
namedescription
findings-countTotal number of findings
critical-countNumber of critical findings
sarif-filePath to SARIF output file
sbom-filePath to CycloneDX SBOM file (if generated)