Deptrust
未认领deptrust is a CLI that checks package versions for known vulnerabilities across npm, PyPI, crates.io, Go modules, RubyGems, NuGet, Maven, Packagist, pub.dev, CocoaPods, Hex.pm, Hackage, GitHub Actions, and more. It runs locally as a CLI and as an MCP server, comes with a skill, and a hook.
安装
npx @clidey/deptrust install更多AI & ML服务器
浏览完整目录安全概况
已认领和已认证的服务器每周接受一次静态扫描,显示代码能触及的范围(外部服务、环境变量、shell 命令、代理配置目录)以及带有已知公告的依赖。认领此列表即可获得。 安全概况的工作原理
文档中列出的工具 (3)
内容来自项目文档。服务器握手不会验证每个工具的说明或行为。
check_package
Checks a package version and returns known vulnerabilities plus a recommendation.
compare_versions
Compares a current version and target version, including resolved and added vulnerabilities.
suggest_safe_version
Checks the latest version first. If latest is not allowed, checks provider-reported fixed versions first, then older known versions, and suggests the newest version with an allow recommendation.