THE PRODUCT

Make dependency risk
clear enough to act on.

DepShield is a local-first Windows application for direct and locally evidenced transitive dependency review. It combines vulnerability intelligence with a graph, SBOM exports, local history, and reports.

FROM MANIFEST TO REVIEW

A focused workflow.
Useful at every step.

01

Discover

Select a project and review supported manifests alongside local evidence for transitive dependencies.

PROJECT INPUT
02

Assess

Look up package metadata with OSV and enrich available findings with NVD, EPSS, and CISA KEV information.

VULNERABILITY DATA
03

Prioritize

Review the provider data alongside DepShield's separate derived risk score. Unknowns and provider errors remain explicit.

RISK CONTEXT
04

Document

Keep local history, create JSON reports, verify report modification, and export supported SBOM formats.

LOCAL EVIDENCE

DIRECT + TRANSITIVE

See the path from your project to each package.

DepShield starts with declared dependencies and adds transitive packages when local ecosystem evidence supports the relationship. Missing evidence stays visible as a coverage limit.

Python

requirements.txt plus matching local .venv distribution metadata. Missing or ambiguous metadata can leave partial coverage.

Node.js

package-lock.json packages graph. Yarn and pnpm transitive graphs are not supported in this build.

Go

go.mod plus available local module-cache metadata. Missing local module metadata can leave a partial graph.

01 / VULNERABILITY INTELLIGENCE

More context.
Clearer review.

DepShield uses OSV for vulnerability matching. Optional enrichment adds CVE, exploit probability, and known-exploited catalog context when those services return it.

  • Provider severity stays distinct from derived risk
  • Missing enrichment is not hidden
  • Service failures are not marked SAFE
ILLUSTRATIVE EXAMPLENot a live scan result
example-package1.4.2 → 1.4.7
SAMPLE 3.4
ILLUSTRATIVE ADVISORY VULNERABLE
CVSS8.1illustrative
EPSS5.6%illustrative
CISA KEVNocatalog check
DepShield risk3.4 / 100.4×8.1 + 3×0.056
Fixed version1.4.7 Review available fix

RISK METHODOLOGY

One score. Three signals.

CVSS describes severity, EPSS contributes exploit probability, and CISA KEV flags known exploitation. The score supports review; it does not predict attacks.

DEPSHIELD DERIVED RISK · 0–10min(10, 0.4 × CVSS + 3 × EPSS + 2 × KEV)

CVSS uses 0–10; EPSS uses 0–1; KEV is 1 if listed, otherwise 0. Direct or transitive status does not affect the score. Provider severity stays separate.

02 / DEPENDENCY GRAPH

See how relationships
shape the review.

Inspect the relationships represented by local scan data. Pan, zoom, and open package details in the desktop workspace.

Graph coverage follows available local evidence; it is not guaranteed to be a complete resolved dependency tree.

03 / SBOM & REPORTING

From component inventory
to reviewable evidence.

Export CycloneDX and SPDX JSON. Generate local scan reports and check whether a report has changed against its saved SHA-256 reference.

01
Software bill of materialsStructured component inventory
JSON
formatCycloneDX 1.5
formatSPDX 2.3
sourceAvailable scan graph
Exportable from Dependencies
02
Security reportLocal scan evidence
JSON
scan summarydependency findingsprovider context
SHA-256Check whether this report has changed

Preview only. Reports reflect declared or discovered dependencies and available provider data.

CycloneDX 1.5Structured JSON component inventory
SPDX 2.3Structured JSON component inventory
Local historyScan records in SQLite on this device

Report modification detection is not cryptographic authenticity, non-repudiation, or proof of authorship.

04 / LOCAL-FIRST ARCHITECTURE

Project analysis belongs
on your computer.

Project manifests and findings are handled by the desktop application. Vulnerability providers receive only required lookup metadata; no project source contents are intentionally included.

Read the privacy model
PUBLIC VULNERABILITY SOURCES
OSVNVDEPSSCISA KEV

Only the metadata needed for lookups leaves the device.

package metadata
and CVE identifiers
YOUR COMPUTERAnalysis and project files stay here
D
DepShieldDesktop application
LOCAL
FindingsDependency graphSBOMReportsScan history
i Project contents, paths, credentials, and Git history are not intentionally included in provider requests.

05 / SCAN HISTORY

A record for the next review.

Completed scans are stored locally, so you can return to their findings and reporting context on the same device.

LOCAL SQLITENo hosted scan history

FIRST PUBLIC RELEASE

DepShield for Windows. Coming soon.

Read the documentation while the first public release completes validation.

Windows release — coming soon