Scan dependencies across multiple ecosystems with typosquat detection.
- Multi-ecosystem: Cargo, npm, PyPI, Go
- Typosquat detection: Levenshtein-based similarity check against known packages
- Multiple lockfile formats: Cargo.lock, package-lock.json, requirements.txt, go.mod, poetry.lock, Pipfile.lock
- JSON output: For automation and CI integration
- Rich terminal output: Tables, panels, progress bars
pip install depscanOr from source:
git clone https://github.com/yunaremaia/depscan.git
cd depscan
pip install -e .# Scan current directory
depscan scan .
# Scan a specific path
depscan scan /path/to/project
# Output as JSON
depscan scan . --json-output > deps.json
# List all dependencies
depscan list-deps .
# Check a specific package
depscan check requests 2.28.0
# Show supported ecosystems
depscan info| Ecosystem | File | Supported Versions / Details | Status |
|---|---|---|---|
| Cargo | Cargo.lock | Cargo packages | ✅ |
| npm | package-lock.json | lockfileVersion 1, 2, and 3 (direct & nested dependencies, packages) |
✅ |
| PyPI | requirements.txt | Pinned dependencies | ✅ |
| PyPI | poetry.lock | Poetry dependencies | ✅ |
| PyPI | Pipfile.lock | Default & develop dependencies | ✅ |
| Go | go.mod | Require directives & replace blocks | ✅ |
Scan a directory for dependencies and detect potential issues.
depscan scan . --typosquat # Enable typosquat detection (default)
depscan scan . --no-typosquat # Disable typosquat detection
depscan scan /path/to/project --json-output # JSON outputList all dependencies found in a directory.
depscan list-deps .
depscan list-deps /path/to/project --json-outputCheck a specific dependency name for typosquat potential.
depscan check raquests 1.0.0 # ⚠ Potential typosquat of "requests"
depscan check requests 2.28.0 # ✓ No issuesShow supported ecosystems and formats.
depscan uses Levenshtein edit distance to detect potential typosquats:
- Distance ≤ 2: Flagged as potential typosquat
- Known packages: Whitelisted to avoid false positives
- Ecosystem-aware: Checks against common package names
Example:
⚠ Potential typosquat detected!
raquests is similar to requests
Both JSON outputs include a $schema key pointing at the published schema, so consumers can validate before parsing.
Validated by schemas/depscan-output.json.
{
"$schema": "https://raw.githubusercontent.com/yunaremaia/depscan/main/schemas/depscan-output.json",
"total": 42,
"typosquats": [
{
"name": "raquests",
"version": "1.0.0",
"target": "requests"
}
],
"by_ecosystem": {
"pypi": 25,
"npm": 17
}
}Fields:
total(integer) — total dependencies found across all lockfiles and manifeststyposquats(array) — dependencies whose names are near-misses of popular packagesname— the dependency name as written in the manifestversion— pinned version of the dependencytarget— the well-known package name it appears to imitate
by_ecosystem(object) — dependency count per ecosystem (cargo,npm,pypi)
Validated by schemas/depscan-list-deps.json.
[
{
"name": "requests",
"version": "2.31.0",
"ecosystem": "pypi"
}
]Fields:
name— dependency nameversion— pinned version from the lockfile or manifestecosystem— one ofcargo,npm,pypi
depscan scan . --json-output | python3 -c "
import json, sys, jsonschema
jsonschema.validate(json.load(sys.stdin), json.load(open('schemas/depscan-output.json')))
"# Setup
git clone https://github.com/yunaremaia/depscan.git
cd depscan
pip install -e ".[dev]"
# Run tests
pytest
# Run tests with coverage
pytest --cov=depscanContributions welcome! See CONTRIBUTING.md for guidelines.
MIT