SARTHAK2511/dsh-cve-audit
Live CVE/supply-chain audit for your workspace's own project dependencies (npm/pip/go), backed by OSV.dev, with a cve_audit tool plus optional automatic re-scan on lockfile changes.
A live CVE / supply-chain audit for the dependencies of the codebase the agent is working in. The README's framing against existing dsh security plugins (dsh-plugin-vetting, dsh-plugin-sentinel, upstream-radar) is that those audit the plugin ecosystem itself, while none scan the lockfiles of your actual project. This plugin reads package-lock.json, requirements.txt or go.sum from the workspace, batch-queries OSV.dev, and reports known CVEs sorted by severity — both as a real cve_audit tool the agent can call (for example cve_audit({ path: "." })) and optionally re-run automatically whenever a lockfile changes.
Install
dsh plugin add @dsh-plugins/dsh-cve-auditREADME Install section quoted verbatim. Registry-verified live 2026-09-15: @dsh-plugins/dsh-cve-audit returned HTTP 404 on registry.npmjs.org, so no npm ownership or version claim is made — the README's command is reproduced as published and should be verified before relying on it.
Compatibility
Reads lockfiles in the workspace (package-lock.json, requirements.txt, go.sum) and batch-queries OSV.dev, which the README notes is free and needs no API key. It is scoped to auditing your project's own dependencies, not the harness's plugins.
Details
- Repo: SARTHAK2511/dsh-cve-audit
- Category: Tools & Capabilities
- Stars: 1
- Version: README does not pin a version (npm name did not resolve on 2026-09-15)
- Last push: 2026-08-15
- First seen: 2026-08-15
Recent updates
The README documents the tool and its configuration rather than a release-by-release changelog; the npm name did not resolve when checked on 2026-09-15.
FAQ
- How do I install it?
- The README's command is dsh plugin add @dsh-plugins/dsh-cve-audit; the npm name did not resolve on 2026-09-15, so verify availability before relying on it.
- Which files does it scan?
- The README names package-lock.json, requirements.txt and go.sum in the workspace.
- Does it need an API key?
- No — the README says it queries OSV.dev, which is free and requires no API key.
Alternatives
1624318455/dsh-plugin-tavily · 6Mikao9/dsh-wsl-workspace · 863683348/dsh-plugin-finance-data