PRODUCT DOCUMENTATION

Understand the scan.
Understand its limits.

DepShield is a local-first Windows desktop application. This guide describes the current product behavior; the first public release is coming soon.

Getting started

The Windows release is currently in final validation and is not publicly downloadable. Once available, the desktop workflow begins by selecting a local project. DepShield identifies supported dependency manifests and presents scan results for review. No account on this website is needed.

Check release status →

How DepShield works

  1. Read supported project manifests and available local dependency evidence.
  2. Send required package name, version, and ecosystem metadata to OSV for vulnerability matching.
  3. Add available NVD/CVSS, EPSS, and CISA KEV context for identified CVEs.
  4. Present statuses, derived risk, dependency relationships, and local export options.

External provider availability affects completeness. Source code is not uploaded to OSV.

Supported ecosystems

ProjectDirect evidenceTransitive evidence
Pythonrequirements.txtMatching local .venv distribution metadata
Node.jsnpm manifest and lock datapackage-lock.json packages graph
Gogo.modAvailable local module-cache metadata

Yarn and pnpm transitive graphs are not supported. Missing or ambiguous local metadata can yield partial coverage.

Dependency discovery

Direct dependencies are declared by a project. Transitive dependencies are packages brought in through other packages. DepShield shows transitive relationships only when supported local evidence identifies them. It does not claim to resolve every installed package or dependency path.

Vulnerability states

VULNERABLE
OSV matched at least one advisory for the identified package and version.
SAFE
The lookup completed and returned no matched advisory for that identified package and version. This is not a guarantee of security.
UNKNOWN
Version or other required information was insufficient to determine a result.
ERROR
A provider, network, or processing failure prevented a reliable result. Errors are never treated as safe.

Risk scoring

DepShield keeps provider severity separate from its own derived score. Severity (CVSS), exploit probability (EPSS), and known exploitation (CISA KEV) are combined when available:

Risk = min(10, 0.4 × CVSS + 3 × EPSS + 2 × KEV)

CVSS is 0–10. EPSS is a probability from 0–1. KEV is 1 if listed, otherwise 0. Directness does not contribute. Missing enrichment remains visible; the score does not predict attacks.

Dependency graph

The desktop graph visualizes project-to-package relationships in the available scan evidence. It helps trace which direct dependency leads to a transitive package and a finding. Incomplete local metadata can produce a partial graph.

Software bill of materials

Export component inventories as CycloneDX 1.5 JSON or SPDX 2.3 JSON from the available scan graph. The inventory reflects discovered data; it is not a guarantee of complete resolved coverage.

Reports & verification

DepShield generates local JSON reports. A saved SHA-256 reference can determine whether an exported report has changed. This is modification detection, not proof of who created the report, cryptographic authenticity, or protection against someone changing both the report and local reference.

Scan history

Scan records are kept in local SQLite storage on the device. Reports and SBOMs are local exports. Local owner authentication controls application access; it does not encrypt SQLite or exported files.

Privacy & security model

Project source analysis stays on the user’s machine. Only metadata needed for vulnerability intelligence is sent to configured providers: package name, version, and ecosystem to OSV; CVE identifiers for NVD and EPSS; and retrieval of the public CISA KEV catalog. The static website has no scan upload, account, tracking script, or application database. A future host may keep ordinary request logs.

Current limitations

Dependency coverage varies with manifest support and local evidence. Yarn and pnpm transitive graphs are not in the current build. Provider outages and unresolved versions can leave findings unknown or in error. A clean result does not guarantee that a project is secure or that every vulnerability has been detected.

Frequently asked questions

Can I download DepShield now?

Not yet. The first public Windows release is in final validation.

Does my source code go to the website or OSV?

No source code is uploaded. The desktop app sends only required lookup metadata to vulnerability providers.

Does a SAFE result mean my project is secure?

No. It means that the completed lookup found no matching advisory for that identified package and version.

Does SHA-256 prove report authorship?

No. It only supports modification detection against a reliable local reference.