Supported ecosystems
dagsec reads these files in every directory of the repository (up to 8 levels deep, skipping build, vendor and hidden directories).
Files
| Ecosystem | File | What dagsec reads | Used for |
|---|---|---|---|
| npm | package-lock.json, npm-shrinkwrap.json | Every installed package (lockfile v1, v2 and v3) | Vulnerabilities, SBOM |
| npm | yarn.lock | Every entry, Yarn classic and Berry; workspace, link, file, portal, patch and git entries are skipped | Vulnerabilities, SBOM |
| npm | pnpm-lock.yaml | Every package key (lockfile v5, v6 and v9) | Vulnerabilities, SBOM |
| npm | package.json | dependencies; file:, link:, workspace:, git and URL specs are skipped; npm: aliases resolve to the real package | Health score |
| PyPI | poetry.lock | Every package | Vulnerabilities, SBOM |
| PyPI | requirements.txt | Names for the health score; == pins for vulnerabilities | Both |
| crates.io | Cargo.lock | Every package from a registry (path and git crates skipped) | Vulnerabilities, SBOM |
| crates.io | Cargo.toml | [dependencies] and [workspace.dependencies], following package = renames; path and git crates skipped | Health score |
| Go | go.mod | Every require, direct and // indirect | Vulnerabilities, SBOM |
| Maven | pom.xml | <dependency> entries with a literal version, a ${property} defined in the same pom, or ${project.version} | Vulnerabilities, SBOM |
| Maven | gradle.lockfile | Every group:artifact:version | Vulnerabilities, SBOM |
| Maven | build.gradle, build.gradle.kts | Quoted "group:artifact:version" coordinates | Vulnerabilities, SBOM |
| Maven | libs.versions.toml | [libraries] with a version or version.ref | Vulnerabilities, SBOM |
| NuGet | packages.lock.json | Every resolved package per target framework (project references skipped) | Vulnerabilities, SBOM |
| NuGet | *.csproj, *.fsproj, *.vbproj | <PackageReference> with a Version attribute or element | Vulnerabilities, SBOM |
| NuGet | Directory.Packages.props | <PackageVersion> (central package management) | Vulnerabilities, SBOM |
| NuGet | packages.config | <package id version> | Vulnerabilities, SBOM |
Only exact versions can be checked for vulnerabilities. Ranges ([1.0,2.0)), floating versions (1.*, 1.+) and unresolved properties are skipped. Commit a lockfile to get complete results.
Skipped directories
node_modules, target, vendor, venv, __pycache__, site-packages, dist, build, obj, bin, and every directory whose name starts with a dot.
Names
| Ecosystem | Package name format | Example |
|---|---|---|
| npm | Name, with scope | @types/node |
| PyPI | Normalized per PEP 503: lowercase, _ and . become - | flask-login |
| crates.io | Crate name | serde |
| Go | Module path | github.com/gin-gonic/gin |
| Maven | groupId:artifactId | org.apache.logging.log4j:log4j-core |
| NuGet | Package ID (case-insensitive) | Newtonsoft.Json |
Not supported yet
Ruby (Bundler), PHP (Composer), Swift, Dart and Elixir.