Skip to content

Command line ​

The dagsec binary runs anywhere x86-64 Linux runs: other CI systems, containers, your own machine. It's the same scanner the GitHub Action and GitLab template use.

Download ​

The binary is served to API keys:

sh
curl -fsS -o dagsec \
  -H "Authorization: Bearer $DAGSEC_API_KEY" \
  "https://app.dagsec.net/api/action/binary?repo=OWNER/REPO"
chmod +x dagsec

Each download counts as one CI run. Outside GitHub Actions and gitlab.com CI there is no signed identity token, so the repository is self-reported and a paid plan is required. See HTTP API.

scan ​

sh
dagsec scan [PATH] [OPTIONS]
OptionDefaultMeaning
PATH.Directory inside the git repository to scan
--fail-under <N>40Fail when a direct dependency scores below N (0 to 100)
--since <REV>noneCheck only commits not reachable from REV, such as a pull request's base commit
--max-commits <N>allCheck only the N most recent commits
--format <F>terminalterminal, markdown or json
--no-verifyoffDon't ask GitHub, Stripe or Slack whether leaked credentials still work

markdown is what pull request comments show; json is described in Report format.

Exit codes ​

CodeMeaning
0Passed
1Findings: see what fails
2The scan couldn't run, for example the path isn't a git repository

Examples ​

sh
# Everything, in the terminal
dagsec scan

# A pull request in any CI, Markdown for a comment
dagsec scan --since "$BASE_SHA" --format markdown > report.md

# Stricter dependencies, machine-readable output
dagsec scan --fail-under 60 --format json > report.json

sbom ​

sh
dagsec sbom [PATH] [-o FILE] [--name NAME]

Writes a CycloneDX 1.5 SBOM from lockfiles. See SBOM export.

Environment ​

VariableEffect
GITHUB_TOKENRaises GitHub API rate limits for repository statistics used by the health score. Sent only to api.github.com.

Registry and OSV answers are cached for 24 hours in ~/.cache/pkgrisk/cache.db.