Skip to content

Known vulnerabilities ​

dagsec checks every package version your lockfiles pin, direct and transitive, against OSV.dev. OSV aggregates GitHub Security Advisories, the Python Packaging Advisory Database, RustSec, the Go vulnerability database and more, so one query covers every ecosystem dagsec reads.

What is checked ​

The exact versions from lockfiles and pinned manifests: see Supported ecosystems for the files. A dependency listed only as a range (^1.2.0) with no lockfile can't be checked for vulnerabilities, because the installed version isn't known; it still gets a health score.

Severity ​

Each vulnerability gets the severity its advisory states:

SeverityFails the scan
criticalYes
highYes
moderate (or medium)No, reported only
lowNo, reported only
unknownNo, reported only

The fix ​

For each vulnerability dagsec reads the advisory's affected ranges and finds the fixed event that closes the range containing your version. The report's Upgrade to column is the highest of these across a package's vulnerabilities, which is the lowest version that fixes all of them. When some advisories have no fix yet, the column says how many. Go versions are shown with the leading v that go.mod uses, such as v0.31.0.

Duplicates ​

One problem is often published under several IDs: a GitHub advisory (GHSA), a CVE, a PyPA ID (PYSEC). dagsec keeps one entry per package version, preferring an entry with a known severity and then the GitHub advisory, and shows the CVE when there is one.

In the report ​

Vulnerabilities are grouped per installed package, worst first:

PackageInstalledUpgrade toVulnerabilities
lodash4.17.44.18.01 critical, 3 high, 4 moderate

A collapsed All advisories table below lists every one, with severity, package, advisory link, fixed version and summary. Pull request comments list up to 30 advisories and count the rest.

If OSV.dev can't be reached, the report says "vulnerability check unavailable" rather than showing an empty list, and vulnerabilities don't fail that scan.

Alerts for new vulnerabilities ​

Advisories are published every day for versions you already use. Vulnerability alerts email you when a new critical or high advisory affects a package version from your scans.