Command line
The dagsec binary runs anywhere x86-64 Linux runs: other CI systems, containers, your own machine. It's the same scanner the GitHub Action and GitLab template use.
Download
The binary is served to API keys:
sh
curl -fsS -o dagsec \
-H "Authorization: Bearer $DAGSEC_API_KEY" \
"https://app.dagsec.net/api/action/binary?repo=OWNER/REPO"
chmod +x dagsecEach download counts as one CI run. Outside GitHub Actions and gitlab.com CI there is no signed identity token, so the repository is self-reported and a paid plan is required. See HTTP API.
scan
sh
dagsec scan [PATH] [OPTIONS]| Option | Default | Meaning |
|---|---|---|
PATH | . | Directory inside the git repository to scan |
--fail-under <N> | 40 | Fail when a direct dependency scores below N (0 to 100) |
--since <REV> | none | Check only commits not reachable from REV, such as a pull request's base commit |
--max-commits <N> | all | Check only the N most recent commits |
--format <F> | terminal | terminal, markdown or json |
--no-verify | off | Don't ask GitHub, Stripe or Slack whether leaked credentials still work |
markdown is what pull request comments show; json is described in Report format.
Exit codes
| Code | Meaning |
|---|---|
0 | Passed |
1 | Findings: see what fails |
2 | The scan couldn't run, for example the path isn't a git repository |
Examples
sh
# Everything, in the terminal
dagsec scan
# A pull request in any CI, Markdown for a comment
dagsec scan --since "$BASE_SHA" --format markdown > report.md
# Stricter dependencies, machine-readable output
dagsec scan --fail-under 60 --format json > report.jsonsbom
sh
dagsec sbom [PATH] [-o FILE] [--name NAME]Writes a CycloneDX 1.5 SBOM from lockfiles. See SBOM export.
Environment
| Variable | Effect |
|---|---|
GITHUB_TOKEN | Raises GitHub API rate limits for repository statistics used by the health score. Sent only to api.github.com. |
Registry and OSV answers are cached for 24 hours in ~/.cache/pkgrisk/cache.db.