{"repo":"clidey/deptrust","free":true,"listed":false,"github":"https://github.com/clidey/deptrust","clone":"git clone https://github.com/clidey/deptrust.git","description":"deptrust is a CLI that checks package versions for known vulnerabilities across npm, PyPI, crates.io, Go modules, RubyGems, NuGet, Maven, Packagist, pub.dev, CocoaPods, Hex.pm, Hackage, GitHub Actions, and more. It runs locally as a CLI and as an MCP server, comes with a skill, and a hook.","language":"Go","stars":61,"topics":["ai","cli","golang","java","javascript","maven","mcp","npm","pypi","ruby"],"license":"MIT","category":"mcp-servers","readme_excerpt":"deptrust deptrust is a CLI that checks package versions for known vulnerabilities across npm, PyPI, crates.io, Go modules, RubyGems, NuGet, Maven, Packagist, pub.dev, CocoaPods, Hex.pm, Hackage, GitHub Actions, and more. It runs locally as a CLI and as an MCP server. It calls public package registry and OSV APIs directly; there is no hosted deptrust service to trust or configure. This tool was born out of the frustration that is AI agents constantly using old versions. Contents - Scope - CLI Usage - Install - Agent Setup - Manual MCP Setup - MCP Tools - Skill-Only Use - Troubleshooting Scope Supported ecosystems: - npm, including scoped packages like @clidey/ux - PyPI - Cargo / crates.io - Go modules - RubyGems - NuGet - Maven, using groupId:artifactId package names - Packagist / Composer, using vendor/package package names - pub.dev - CocoaPods - Hex.pm - Hackage - GitHub Actions, using owner/repo package names and tags, branch refs, or commit SHAs as versions deptrust currently reports known vulnerabilities and gives a simple recommendation: Highest known severity Recommendation --- --- critical block high block medium / unknown review low allow none found allow allow means no blocking known vulnerability was found in the public data sources. It does not prove that a package is safe. deptrust also emits risk signals that are not CVEs. For example, a version published in the last 72 hours is marked for review so an agent does not blindly install a brand-new release. Advisory","default_branch":null,"files":null,"tree":[],"storefront":"/r/clidey","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/clidey/deptrust/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}