Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
depsguard — Harden your package manager configs against supply chain attacks. | Kitploit
Tools/GitHubGitHub/arnica/depsguard
Vulnerability AnalysisConfiguration AuditingCloud SecurityDevSecOpsSecret DetectionSupply Chain Security
GitHubarnica/depsguard

depsguard

Harden your package manager configs against supply chain attacks.

View Repository
38218182 months agoReviewed by Kitploit
Website

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

depsguard

CI Security Audit crates.io License: MIT MSRV

     _                                          _
  __| | ___ _ __  ___  __ _ _   _  __ _ _ __ __| |
 / _` |/ _ \ '_ \/ __|/ _` | | | |/ _` | '__/ _` |
| (_| |  __/ |_) \__ \ (_| | |_| | (_| | | | (_| |
 \__,_|\___| .__/|___/\__, |\__,_|\__,_|_|  \__,_|
           |_|        |___/

Guard your dependencies against supply chain attacks. Single static binary, zero Rust crate dependencies.

By [arnica]

Table of contents

  • Overview
  • Install
  • Usage
  • What gets checked
  • Config file locations
  • Urgent security fix
  • Backups and restore
  • How it works
  • Troubleshooting
  • Help & feedback
  • Guides
  • See also
  • License

Overview

DepsGuard looks for npm, pnpm, yarn, bun, uv, pip, poetry, and aube on your machine, reads their config files, compares them to recommended supply-chain settings, and can apply fixes interactively. It also scans for Renovate and Dependabot configs in your repos. It never runs package installs; it only edits config files you approve, and it writes backups before any change.

Key features

  • Interactive TUI: scan, review, toggle fixes, apply
  • scan subcommand for read-only reporting
  • restore subcommand to pick a backup and roll back a file
  • Cross-platform: Linux, macOS, Windows
  • No bundled third-party Rust crates (stdlib + small amount of platform FFI for the terminal)

Tech stack

AreaDetails
LanguageRust (MSRV 1.74, see Cargo.toml)
CLI / TUIsrc/main.rs, src/ui.rs, src/term.rs
Config logicsrc/manager.rs, src/fix.rs
WebsiteStatic site under docs/ (separate from the binary)

Install

Prebuilt binaries

Each GitHub Release includes archives for:

  • Linux: x86_64 (glibc), x86_64 (musl), aarch64 (glibc)
  • macOS: Intel and Apple Silicon
  • Windows: x86_64 ZIP containing depsguard.exe

Download the archive for your platform, unpack it, and put the binary on your PATH.

Verify integrity using the matching .sha256 file next to each asset on the release page.

Install by platform

Linux (Debian/Ubuntu via APT)

sudo install -d -m 0755 /etc/apt/keyrings
curl -fsSL https://depsguard.com/apt/gpg.key | sudo gpg --dearmor -o /etc/apt/keyrings/depsguard.gpg
echo "deb [arch=amd64,arm64 signed-by=/etc/apt/keyrings/depsguard.gpg] https://depsguard.com/apt stable main" | sudo tee /etc/apt/sources.list.d/depsguard.list >/dev/null
sudo apt update
sudo apt install depsguard

macOS / Linux (Homebrew)

# Homebrew
brew install depsguard

DepsGuard is in homebrew-core, so no custom tap is required.

Migrating from the old arnica/depsguard tap? Switch to the core formula once:

brew uninstall depsguard
brew untap arnica/depsguard
brew update
brew install depsguard

Windows

# WinGet
winget install Arnica.DepsGuard

# Scoop
scoop bucket add depsguard https://github.com/arnica/depsguard
scoop install depsguard

Or download manually via PowerShell:

$zip = "$env:TEMP\\depsguard.zip"
Invoke-WebRequest -Uri "https://github.com/arnica/depsguard/releases/latest/download/depsguard-x86_64-pc-windows-msvc.zip" -OutFile $zip
Expand-Archive -LiteralPath $zip -DestinationPath "$env:TEMP\\depsguard" -Force
Copy-Item "$env:TEMP\\depsguard\\depsguard.exe" "$HOME\\AppData\\Local\\Microsoft\\WindowsApps\\depsguard.exe" -Force
depsguard.exe --help

crates.io

cargo install depsguard

Requires a Rust toolchain with cargo.

Package managers (when published by your vendor)

If your organization ships DepsGuard via Homebrew, Scoop, or WinGet, use their instructions. Setting up or automating those channels (Homebrew core PRs, buckets, WinGet PRs, CI secrets) is maintainer documentation; see AGENTS.md under Release & distribution.

App stores / package managers

ChannelLinuxmacOSWindowsInstall command
APT (custom repo)yesnonosudo apt install depsguard (after repo setup above)
crates.ioyesyesyescargo install depsguard
Homebrew (homebrew-core)yesyesnobrew install depsguard
Scoop (custom bucket)nonoyesscoop bucket add depsguard https://github.com/arnica/depsguard ; scoop install depsguard
WinGetnonoyeswinget install Arnica.DepsGuard

Update to the latest version

Use whichever channel you installed with:

ChannelUpgrade command
Homebrewbrew update && brew upgrade depsguard
APT (custom repo)sudo apt update && sudo apt install --only-upgrade depsguard
crates.iocargo install --force depsguard (reinstalls the latest release)
Scoopscoop update && scoop update depsguard
WinGetwinget upgrade Arnica.DepsGuard

Check your installed version any time with depsguard --version, and see the releases page for the newest version.

Build from source

git clone https://github.com/arnica/depsguard.git
cd depsguard
cargo build --release

The binary is target/release/depsguard (.exe on Windows). Rust 1.74+ is required.

Usage

depsguard              # interactive: scan, choose fixes, apply
depsguard scan         # report only; no writes (exits 1 if action is needed)
depsguard --no-search  # skip recursive file search, check local configs only
depsguard restore      # restore from a previous backup
depsguard --help       # CLI help

How to use

Download Tool