VOOZH about

URL: https://apify.com/scrapeworks/dependency-risk-audit

โ‡ฑ Dependency Risk Audit - Vulnerability & Health Scanner ยท Apify


๐Ÿ‘ Dependency Supply-Chain Risk Audit avatar

Dependency Supply-Chain Risk Audit

Pricing

from $1.00 / 1,000 results

Go to Apify Store

Dependency Supply-Chain Risk Audit

Audit your package.json or requirements.txt for supply-chain risk: known vulnerabilities (OSV), deprecated/abandoned packages, and a project-level risk score.

Pricing

from $1.00 / 1,000 results

Rating

0.0

(0)

Developer

๐Ÿ‘ Nicolas van Arkens

Nicolas van Arkens

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

22 days ago

Last modified

Share

Dependency Supply-Chain Risk Audit ๐Ÿ›ก๏ธ

Paste your package.json or requirements.txt and get a complete supply-chain risk report for every dependency โ€” known vulnerabilities, deprecated and abandoned packages, stale releases, and licensing gaps โ€” rolled up into one project-level risk verdict.

Most package scrapers hand you raw metadata for one package at a time. This audits your whole dependency list at once and tells you what actually matters: is my project safe to ship?

What it checks per dependency

  • ๐Ÿšจ Known vulnerabilities โ€” cross-referenced against the OSV database (CVEs and security advisories across npm and PyPI)
  • โšฐ๏ธ Deprecated / yanked packages โ€” flagged as hard risks
  • ๐Ÿ•’ Staleness โ€” packages with no release in 1, 2, or 3+ years
  • ๐Ÿ“œ Licensing โ€” missing or unclear licenses
  • ๐Ÿ”— Source repo โ€” the linked GitHub/source URL for deeper review

Each dependency gets a 0-100 risk score and a level (Minimal โ†’ Low โ†’ Medium โ†’ High โ†’ Critical), with concrete flags explaining why.

Project-level summary

The first result is an aggregate verdict for the whole project:

{
"recordType":"project_summary",
"projectRiskLevel":"Critical",
"totalDependencies":42,
"vulnerableDependencies":3,
"deprecatedDependencies":2,
"staleDependencies":5,
"riskBreakdown":{"Critical":1,"High":2,"Medium":4,"Low":6,"Minimal":29},
"summary":"42 dependencies analyzed: 3 with known vulnerabilities, 2 deprecated, 5 stale. Overall risk: Critical."
}

Use cases

  • Pre-deployment security gate โ€” audit dependencies before every release
  • Tech due diligence โ€” assess a codebase's supply-chain exposure
  • Continuous monitoring โ€” schedule it to re-audit and catch newly-disclosed CVEs or freshly-deprecated packages
  • Dependency cleanup โ€” find the abandoned and risky packages to replace

Input

FieldDescription
Manifest contentsPaste a full package.json or requirements.txt.
Manifest typeAuto-detect, or force npm / PyPI.
Check vulnerabilitiesToggle the OSV vulnerability lookup.
Max dependenciesCap how many to audit.

Output

One project_summary record, then one record per dependency with its risk score, level, vulnerability count, flags, version, release date, license, and repo link. Export to JSON, CSV, or Excel, or pull via the Apify API โ€” wire it into CI, Slack, or Sheets for automated alerts.

Notes on the vulnerability data

Vulnerability checks use the free, public OSV.dev API maintained by Google's open-source security team, covering npm and PyPI advisories. If the vulnerability service is briefly unavailable, the audit still completes using health signals and clearly marks which packages were scored without vulnerability data โ€” the run never fails because of it.

The risk score is a transparent heuristic to help you prioritize review, not a security guarantee. Always combine it with your own judgment for critical systems. Independent tool; not affiliated with npm, PyPI, GitHub, or OSV.

You might also like

Open Source Supply Chain Risk MCP

ryanclinton/open-source-supply-chain-risk-mcp

OSS supply chain risk intelligence with dependency graph propagation, bus-factor analysis, and typosquat detection.

Food Safety Supply Chain MCP Server

ryanclinton/food-safety-supply-chain-mcp

Food safety and supply chain risk intelligence via the Model Context Protocol.

Zentra Actor Supply Chain Inspector

zentrafoundry/zentra-actor-supply-chain-inspector

Audit Actor codebases for supply-chain, dependency, Dockerfile, license, and secret risks.

Supply Chain Intel

fiery_dream/supply-chain-intel

AI-powered supply chain risk monitoring and intelligence. Track disruptions, tariffs, port congestion, and geopolitical events affecting global supply chains.

๐Ÿ‘ User avatar

Cody Churchwell

13

Open Source Software Supply Chain MCP Server

ryanclinton/open-source-software-supply-chain-mcp

OSS dependency risk and SBOM compliance intelligence for application security teams, engineering leadership, and procurement.