How dagsec works
Every scan, wherever it runs, does the same four things to a git checkout.
1. Read the git history
dagsec walks every commit reachable from HEAD, oldest first, and looks at the lines each commit added. A secret committed and deleted later is still found, at the commit that introduced it. Each distinct secret in a file is reported once.
On a pull request, only commits that aren't in the base branch are checked (--since <base commit>), so old findings on the main branch don't block new work. That's why the checkout needs the full history: fetch-depth: 0 on GitHub, GIT_DEPTH: 0 on GitLab. See Leaked secrets.
2. Find the dependencies
dagsec reads manifests and lockfiles in every directory, up to 8 levels deep, skipping node_modules, target, vendor, venv, __pycache__, site-packages, dist, build, obj, bin and hidden directories.
- Lockfiles give the exact installed versions, direct and transitive. These are audited for vulnerabilities and listed in the SBOM.
- Manifests (
package.json,Cargo.toml,requirements.txt) give the direct dependencies. These get a health score.
Packages that live in the repository itself (workspace members, path and git dependencies) are left out, so an unrelated public package with the same name is never scored in their place. See Supported ecosystems.
3. Ask public sources
| Question | Source |
|---|---|
| Known vulnerabilities in a version | OSV.dev, which aggregates GitHub Security Advisories, PyPA, RustSec, the Go vulnerability database and more |
| Latest release, license, downloads | The package's registry: npm, PyPI, crates.io, the Go module proxy, Maven Central, NuGet |
| Maintenance, contributors, stars | The GitHub repository the package links to |
| Does a leaked credential still work | The credential's own provider (GitHub, Stripe, Slack), only in your CI or the GitHub App |
Only package names and versions are sent to these services: never code, file names or personal data. Registry answers are cached for 24 hours.
4. Decide and report
The findings become a pass or fail verdict (rules) and a report: a pull request comment and check, a GitLab merge request comment, a dashboard page, or terminal, Markdown or JSON output from the CLI.
Where the scan runs
| Integration | Runs on | Code leaves your infrastructure? |
|---|---|---|
| GitHub Action, GitLab CI, CLI | Your runner or machine | No. The runner downloads the scanner binary and scans locally. |
| GitHub App, dashboard | dagsec server | Only for the scan: cloned to a temporary directory, deleted when it ends. |
| AI agent integrations | Your machine | No. Only package names, versions and install commands are checked. |