Known vulnerabilities
Exact versions are matched against OSV.dev, which aggregates GitHub Advisory, PyPA and other sources. You get CVSS-based severity, the fixed version and a fix-first order.
Upload your project's dependency files: package-lock.json, yarn.lock, package.json, requirements.txt, pom.xml or build.gradle. We show known vulnerabilities with the fixed version, licenses with a risk class, deprecated and long-unmaintained packages, cloud vendor SDKs and a rough work estimate. Download a CycloneDX SBOM right away.
Files are parsed in your browser and never uploaded. Before the check you'll see exactly which package@version pairs will be sent, and can exclude internal ones.
Drop your dependency files here
Up to 12 files, 15 MB each. A lock file gives the most complete result.
Supported: package-lock.json, npm-shrinkwrap.json, yarn.lock, package.json, requirements*.txt, pom.xml, build.gradle, build.gradle.kts. Not yet: pnpm-lock.yaml, poetry.lock, Pipfile.lock, go.mod, Cargo.lock, composer.lock, Gemfile.lock.
Your files stay with you. Parsing happens in the browser; files are not uploaded. Next you'll see which package@version pairs will be sent to our server and on to the public OSV.dev vulnerability database and the deps.dev package index; internal packages can be excluded. We don't store this list or write it to logs.
Manifests are parsed in your browser; only the package@version pairs you approve are sent to the server. Every finding comes with an explanation and a next step.
Exact versions are matched against OSV.dev, which aggregates GitHub Advisory, PyPA and other sources. You get CVSS-based severity, the fixed version and a fix-first order.
The license is taken from the lock file or registry and classified: permissive, weak or strong copyleft, paid, undetermined. OR and AND expressions follow SPDX rules.
We flag deprecated packages, packages without releases for years, and versions far behind the latest. The risky combo is “unmaintained” plus “vulnerability without a fix”.
See the dependency inventory, known vulnerabilities and license risks before signing off, instead of taking it on trust.
Produce a CycloneDX component list in minutes without setting up tooling in CI.
Find out how many packages need updating and roughly how many hours it takes before planning a sprint or budget.
Download LiMP VPN for free and feel the difference within a minute.
An SBOM (Software Bill of Materials) lists every third-party component of a program with its version and license. It's requested at project acceptance, in security audits and when handing a product over to a customer: it shows what the application is built from and what it relies on.
CycloneDX is an open SBOM format standard. A CycloneDX JSON file is understood by Dependency-Track, vulnerability scanners and most software supply-chain tools.
package.json and requirements.txt usually contain version ranges such as ^4.17.0. Only the lock file knows which version is actually installed. Vulnerability databases match exact versions, so without a lock file the check is incomplete: packages with ranges are listed but not checked.