depproof is a self-hosted dependency security scanner, distributed as a single container image and as a GitHub Action. It resolves the complete transitive tree of third-party dependencies in a project, matches every package against OSV advisory data, and ranks the findings so teams know what to fix first.
Ranking uses signals such as active exploitation (the CISA Known Exploited Vulnerabilities catalog) and, for Maven, npm and .NET, whether a package ever loaded while your own CI tests ran. Nothing is removed; the list is simply put in order. It also classifies every license as allowed, review or forbidden, and writes a CycloneDX SBOM you can hand to a customer or an auditor.
It runs as one container, as a GitHub Action, or as a GitLab CI job, on your own infrastructure. Your source and your findings never leave it, so it also works air-gapped. The output is a self-contained HTML report, a CycloneDX SBOM, and a pass/fail CI gate on a severity you choose.
Supported ecosystems are Java (Maven and Gradle), JavaScript and Node (npm, pnpm, yarn, bun), Python (PyPI), Go (modules) and .NET (NuGet).
Priced per depproof product (the Scanner, and the Hub added to it), never per seat, per committer or per application. The Scanner is free for open-source projects and for organizations under $1M annual revenue.
No comments or reviews, maybe you want to be first?