Skip to content

Supported ecosystems ​

dagsec reads these files in every directory of the repository (up to 8 levels deep, skipping build, vendor and hidden directories).

Files ​

EcosystemFileWhat dagsec readsUsed for
npmpackage-lock.json, npm-shrinkwrap.jsonEvery installed package (lockfile v1, v2 and v3)Vulnerabilities, SBOM
npmyarn.lockEvery entry, Yarn classic and Berry; workspace, link, file, portal, patch and git entries are skippedVulnerabilities, SBOM
npmpnpm-lock.yamlEvery package key (lockfile v5, v6 and v9)Vulnerabilities, SBOM
npmpackage.jsondependencies; file:, link:, workspace:, git and URL specs are skipped; npm: aliases resolve to the real packageHealth score
PyPIpoetry.lockEvery packageVulnerabilities, SBOM
PyPIrequirements.txtNames for the health score; == pins for vulnerabilitiesBoth
crates.ioCargo.lockEvery package from a registry (path and git crates skipped)Vulnerabilities, SBOM
crates.ioCargo.toml[dependencies] and [workspace.dependencies], following package = renames; path and git crates skippedHealth score
Gogo.modEvery require, direct and // indirectVulnerabilities, SBOM
Mavenpom.xml<dependency> entries with a literal version, a ${property} defined in the same pom, or ${project.version}Vulnerabilities, SBOM
Mavengradle.lockfileEvery group:artifact:versionVulnerabilities, SBOM
Mavenbuild.gradle, build.gradle.ktsQuoted "group:artifact:version" coordinatesVulnerabilities, SBOM
Mavenlibs.versions.toml[libraries] with a version or version.refVulnerabilities, SBOM
NuGetpackages.lock.jsonEvery resolved package per target framework (project references skipped)Vulnerabilities, SBOM
NuGet*.csproj, *.fsproj, *.vbproj<PackageReference> with a Version attribute or elementVulnerabilities, SBOM
NuGetDirectory.Packages.props<PackageVersion> (central package management)Vulnerabilities, SBOM
NuGetpackages.config<package id version>Vulnerabilities, SBOM

Only exact versions can be checked for vulnerabilities. Ranges ([1.0,2.0)), floating versions (1.*, 1.+) and unresolved properties are skipped. Commit a lockfile to get complete results.

Skipped directories ​

node_modules, target, vendor, venv, __pycache__, site-packages, dist, build, obj, bin, and every directory whose name starts with a dot.

Names ​

EcosystemPackage name formatExample
npmName, with scope@types/node
PyPINormalized per PEP 503: lowercase, _ and . become -flask-login
crates.ioCrate nameserde
GoModule pathgithub.com/gin-gonic/gin
MavengroupId:artifactIdorg.apache.logging.log4j:log4j-core
NuGetPackage ID (case-insensitive)Newtonsoft.Json

Not supported yet ​

Ruby (Bundler), PHP (Composer), Swift, Dart and Elixir.