Discover
Select a project and review supported manifests alongside local evidence for transitive dependencies.
PROJECT INPUTTHE PRODUCT
DepShield is a local-first Windows application for direct and locally evidenced transitive dependency review. It combines vulnerability intelligence with a graph, SBOM exports, local history, and reports.
FROM MANIFEST TO REVIEW
Select a project and review supported manifests alongside local evidence for transitive dependencies.
PROJECT INPUTLook up package metadata with OSV and enrich available findings with NVD, EPSS, and CISA KEV information.
VULNERABILITY DATAReview the provider data alongside DepShield's separate derived risk score. Unknowns and provider errors remain explicit.
RISK CONTEXTKeep local history, create JSON reports, verify report modification, and export supported SBOM formats.
LOCAL EVIDENCEDIRECT + TRANSITIVE
DepShield starts with declared dependencies and adds transitive packages when local ecosystem evidence supports the relationship. Missing evidence stays visible as a coverage limit.
requirements.txt plus matching local .venv distribution metadata. Missing or ambiguous metadata can leave partial coverage.
package-lock.json packages graph. Yarn and pnpm transitive graphs are not supported in this build.
go.mod plus available local module-cache metadata. Missing local module metadata can leave a partial graph.
01 / VULNERABILITY INTELLIGENCE
DepShield uses OSV for vulnerability matching. Optional enrichment adds CVE, exploit probability, and known-exploited catalog context when those services return it.
RISK METHODOLOGY
CVSS describes severity, EPSS contributes exploit probability, and CISA KEV flags known exploitation. The score supports review; it does not predict attacks.
min(10, 0.4 × CVSS + 3 × EPSS + 2 × KEV)CVSS uses 0–10; EPSS uses 0–1; KEV is 1 if listed, otherwise 0. Direct or transitive status does not affect the score. Provider severity stays separate.
02 / DEPENDENCY GRAPH
Inspect the relationships represented by local scan data. Pan, zoom, and open package details in the desktop workspace.
Graph coverage follows available local evidence; it is not guaranteed to be a complete resolved dependency tree.
03 / SBOM & REPORTING
Export CycloneDX and SPDX JSON. Generate local scan reports and check whether a report has changed against its saved SHA-256 reference.
Preview only. Reports reflect declared or discovered dependencies and available provider data.
Report modification detection is not cryptographic authenticity, non-repudiation, or proof of authorship.
04 / LOCAL-FIRST ARCHITECTURE
Project manifests and findings are handled by the desktop application. Vulnerability providers receive only required lookup metadata; no project source contents are intentionally included.
Read the privacy modelOnly the metadata needed for lookups leaves the device.
05 / SCAN HISTORY
Completed scans are stored locally, so you can return to their findings and reporting context on the same device.
FIRST PUBLIC RELEASE
Read the documentation while the first public release completes validation.
Windows release — coming soon