Keep the project local.
Analysis runs on your machine. Configured providers receive only necessary package or CVE metadata for vulnerability intelligence.
ABOUT DEPSHIELD
DepShield helps developers understand software supply chain risk through local dependency discovery, vulnerability intelligence, and clear security evidence.
Analysis runs on your machine. Configured providers receive only necessary package or CVE metadata for vulnerability intelligence.
Direct and locally evidenced transitive packages can be traced through the dependency graph, with coverage limits made clear.
Unknown versions and provider errors remain distinct. A clean lookup is useful evidence, not a promise that the whole project is secure.
THE PRODUCT PRINCIPLE
DepShield keeps source analysis, scan history, reports, and SBOMs on the user's device. Vulnerability lookups use necessary metadata.
Only the metadata needed for lookups leaves the device.
FIRST PUBLIC RELEASE
Explore the documentation while the first public release completes validation.
Windows release — coming soon