
Harden your package manager configs against supply chain attacks.
_ _
__| | ___ _ __ ___ __ _ _ _ __ _ _ __ __| |
/ _` |/ _ \ '_ \/ __|/ _` | | | |/ _` | '__/ _` |
| (_| | __/ |_) \__ \ (_| | |_| | (_| | | | (_| |
\__,_|\___| .__/|___/\__, |\__,_|\__,_|_| \__,_|
|_| |___/
Guard your dependencies against supply chain attacks. Single static binary, zero Rust crate dependencies.
By [arnica]
DepsGuard looks for npm, pnpm, yarn, bun, uv, pip, poetry, and aube on your machine, reads their config files, compares them to recommended supply-chain settings, and can apply fixes interactively. It also scans for Renovate and Dependabot configs in your repos. It never runs package installs; it only edits config files you approve, and it writes backups before any change.
scan subcommand for read-only reportingrestore subcommand to pick a backup and roll back a file| Area | Details |
|---|---|
| Language | Rust (MSRV 1.74, see Cargo.toml) |
| CLI / TUI | src/main.rs, src/ui.rs, src/term.rs |
| Config logic | src/manager.rs, src/fix.rs |
| Website | Static site under docs/ (separate from the binary) |
Each GitHub Release includes archives for:
x86_64 (glibc), x86_64 (musl), aarch64 (glibc)x86_64 ZIP containing depsguard.exeDownload the archive for your platform, unpack it, and put the binary on your PATH.
Verify integrity using the matching .sha256 file next to each asset on the release page.
sudo install -d -m 0755 /etc/apt/keyrings
curl -fsSL https://depsguard.com/apt/gpg.key | sudo gpg --dearmor -o /etc/apt/keyrings/depsguard.gpg
echo "deb [arch=amd64,arm64 signed-by=/etc/apt/keyrings/depsguard.gpg] https://depsguard.com/apt stable main" | sudo tee /etc/apt/sources.list.d/depsguard.list >/dev/null
sudo apt update
sudo apt install depsguard
# Homebrew
brew install depsguard
DepsGuard is in homebrew-core, so no custom tap is required.
Migrating from the old
arnica/depsguardtap? Switch to the core formula once:brew uninstall depsguard brew untap arnica/depsguard brew update brew install depsguard
# WinGet
winget install Arnica.DepsGuard
# Scoop
scoop bucket add depsguard https://github.com/arnica/depsguard
scoop install depsguard
Or download manually via PowerShell:
$zip = "$env:TEMP\\depsguard.zip"
Invoke-WebRequest -Uri "https://github.com/arnica/depsguard/releases/latest/download/depsguard-x86_64-pc-windows-msvc.zip" -OutFile $zip
Expand-Archive -LiteralPath $zip -DestinationPath "$env:TEMP\\depsguard" -Force
Copy-Item "$env:TEMP\\depsguard\\depsguard.exe" "$HOME\\AppData\\Local\\Microsoft\\WindowsApps\\depsguard.exe" -Force
depsguard.exe --help
cargo install depsguard
Requires a Rust toolchain with cargo.
If your organization ships DepsGuard via Homebrew, Scoop, or WinGet, use their instructions. Setting up or automating those channels (Homebrew core PRs, buckets, WinGet PRs, CI secrets) is maintainer documentation; see AGENTS.md under Release & distribution.
| Channel | Linux | macOS | Windows | Install command |
|---|---|---|---|---|
| APT (custom repo) | yes | no | no | sudo apt install depsguard (after repo setup above) |
| crates.io | yes | yes | yes | cargo install depsguard |
| Homebrew (homebrew-core) | yes | yes | no | brew install depsguard |
| Scoop (custom bucket) | no | no | yes | scoop bucket add depsguard https://github.com/arnica/depsguard ; scoop install depsguard |
| WinGet | no | no | yes | winget install Arnica.DepsGuard |
Use whichever channel you installed with:
| Channel | Upgrade command |
|---|---|
| Homebrew | brew update && brew upgrade depsguard |
| APT (custom repo) | sudo apt update && sudo apt install --only-upgrade depsguard |
| crates.io | cargo install --force depsguard (reinstalls the latest release) |
| Scoop | scoop update && scoop update depsguard |
| WinGet | winget upgrade Arnica.DepsGuard |
Check your installed version any time with depsguard --version, and see the releases page for the newest version.
git clone https://github.com/arnica/depsguard.git
cd depsguard
cargo build --release
The binary is target/release/depsguard (.exe on Windows). Rust 1.74+ is required.
depsguard # interactive: scan, choose fixes, apply
depsguard scan # report only; no writes (exits 1 if action is needed)
depsguard --no-search # skip recursive file search, check local configs only
depsguard restore # restore from a previous backup
depsguard --help # CLI help