LOCAL-FIRST · WINDOWS DESKTOP

Dependency security.
Without surrendering your source code.

Find vulnerable direct and locally evidenced transitive dependencies. Understand risk, generate SBOMs, and keep security evidence on your machine.

Currently in final validation.

Local-firstWindowsSoftware supply chain security
Illustrative relationship diagram · not a product screenshot or scan result
01Dependency discoveryDirect and locally evidenced transitive
02Vulnerability contextOSV with optional enrichment
03Risk reviewClear SAFE / UNKNOWN / ERROR states
04Security evidenceReports and SBOM exports

VULNERABILITY INTELLIGENCE

Don't just find vulnerabilities.
Know what deserves a closer look.

DepShield combines available advisory severity with exploitability context to help you prioritize review. Provider severity and DepShield-derived risk remain distinct, and missing enrichment stays visible.

  • OSV vulnerability matching
  • NVD, EPSS, and CISA KEV enrichment when available
  • SAFE, VULNERABLE, UNKNOWN, and ERROR outcomes
Explore finding details
ILLUSTRATIVE EXAMPLENot a live scan result
example-package1.4.2 → 1.4.7
SAMPLE 3.4
ILLUSTRATIVE ADVISORY VULNERABLE
CVSS8.1illustrative
EPSS5.6%illustrative
CISA KEVNocatalog check
DepShield risk3.4 / 100.4×8.1 + 3×0.056
Fixed version1.4.7 Review available fix

LOCAL-FIRST BY DESIGN

Your code isn't our business.
It stays on your machine.

DepShield reads supported project manifests locally. For vulnerability lookups, it sends only the package metadata a provider needs—not project source files or archives.

PUBLIC VULNERABILITY SOURCES
OSVNVDEPSSCISA KEV

Only the metadata needed for lookups leaves the device.

package metadata
and CVE identifiers
YOUR COMPUTERAnalysis and project files stay here
D
DepShieldDesktop application
LOCAL
FindingsDependency graphSBOMReportsScan history
i Project contents, paths, credentials, and Git history are not intentionally included in provider requests.

DEPENDENCY RELATIONSHIPS

See where the risk
connects to your project.

Trace how direct dependencies connect to locally evidenced transitive packages and where a vulnerability enters the graph.

The graph reflects available manifest or scan graph data; it is not a guarantee of a complete resolved or transitive inventory.

See the product overview

INVENTORY & EVIDENCE

Know what you're shipping.
Keep a record of what you found.

Export structured component inventories and keep scan findings in professional, portable reports.

01
Software bill of materialsStructured component inventory
JSON
formatCycloneDX 1.5
formatSPDX 2.3
sourceAvailable scan graph
Exportable from Dependencies
02
Security reportLocal scan evidence
JSON
scan summarydependency findingsprovider context
SHA-256Check whether this report has changed

Preview only. Reports reflect declared or discovered dependencies and available provider data.

01 / SBOM

Useful component inventories

Export CycloneDX 1.5 or SPDX 2.3 JSON from the dependency data available to the scan.

02 / REPORTS

Reviewable scan evidence

Generate deterministic JSON reports and check whether a referenced report has changed using its local SHA-256 reference.

03 / HISTORY

Local scan history

Keep previous scans in local SQLite storage, on the same device as the application.

SHA-256 provides modification detection while its local reference remains reliable; it is not authentication or proof of authorship.

BUILT FOR PRACTICAL REVIEW

Security signals, in a desktop workflow.

DepShield supports Python, Node.js, and Go using ecosystem-specific local evidence. Coverage can be partial; a clean result does not guarantee that a project is secure.

FIRST PUBLIC RELEASE

DepShield for Windows. Coming soon.

The first public release is in final validation. Explore how the desktop workflow fits together today.

Windows release — coming soon