Skip to content
KitploitKITPLOIT
ツールエクスプロイトブログ
Log in
提出
ツールエクスプロイトブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

フィードお問い合わせプライバシー© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
depsguard — サプライチェーン攻撃に対してパッケージマネージャーの設定を強化します。 | Kitploit
ツール/GitHubGitHub/arnica/depsguard
脆弱性分析構成監査クラウドセキュリティDevSecOpsシークレット検出サプライチェーンセキュリティ
GitHubarnica/depsguard

depsguard

サプライチェーン攻撃に対してパッケージマネージャーの設定を強化します。

リポジトリを見る
38218182ヶ月前Kitploit レビュー済み
ウェブサイト

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

depsguard

CI Security Audit crates.io License: MIT MSRV```text _ _ | | ___ _ __ ___ __ _ _ _ __ _ _ __ | | / |/ _ \ '_ \/ __|/ _ | | | |/ | '__/ _ | | (| | __/ |) _ \ (| | || | (| | | | (| | _,_|_| ./|/_, |_,|_,|| _,| || |___/

Guard your dependencies against supply chain attacks. **Single static binary, zero Rust crate dependencies.**

作者 **[[arnica](https://arnica.io?utm_source=depsguard&utm_medium=referral&utm_campaign=community)]**

## Table of contents

- [概要](#overview)
- [インストール](#install)
- [使い方](#usage)
- [チェックされる内容](#what-gets-checked)
- [設定ファイルの場所](#config-file-locations)
- [緊急セキュリティ修正](#urgent-security-fix)
- [バックアップと復元](#backups-and-restore)
- [仕組み](#how-it-works)
- [トラブルシューティング](#troubleshooting)
- [ヘルプとフィードバック](#help--feedback)
- [ガイド](#guides)
- [関連項目](#see-also)
- [ライセンス](#license)

## 概要

DepsGuardは、お使いのマシン上の**npm**、**pnpm**、**yarn**、**bun**、**uv**、**pip**、**poetry**、**aube**を検出し、それらの設定ファイルを読み取り、推奨されるサプライチェーン設定と比較して、**修正を対話的に適用**できます。また、リポジトリ内の**Renovate**および**Dependabot**の設定もスキャンします。パッケージのインストールは一切実行しません。承認した設定ファイルのみを編集し、変更前には常に**バックアップ**を作成します。

### 主な機能

- 対話型TUI:スキャン、レビュー、修正の切り替え、適用
- 読み取り専用レポート用の`scan`サブコマンド
- バックアップを選択してファイルをロールバックするための`restore`サブコマンド
- クロスプラットフォーム:Linux、macOS、Windows
- サードパーティのRustクレートを同梱しない(標準ライブラリ+端末用の少量のプラットフォームFFI)

### 技術スタック

| 分野 | 詳細 |
|------|---------|
| 言語 | Rust(MSRV **1.74**、`Cargo.toml`を参照) |
| CLI / TUI | `src/main.rs`, `src/ui.rs`, `src/term.rs` |
| 設定ロジック | `src/manager.rs`, `src/fix.rs` |
| Webサイト | `docs/` 配下の静的サイト(バイナリとは別) |

## インストール

### プリビルトバイナリ

各[GitHub Release](https://github.com/arnica/depsguard/releases)には、次のアーカイブが含まれています:

- Linux: `x86_64` (glibc), `x86_64` (musl), `aarch64` (glibc)
- macOS: IntelおよびApple Silicon
- Windows: `x86_64` ZIP(`depsguard.exe`を含む)

お使いのプラットフォームのアーカイブをダウンロードし、解凍して、`PATH`にバイナリを配置してください。

リリースページで各アセットの隣にある対応する`.sha256`ファイルを使用して整合性を検証してください。

### プラットフォーム別のインストール

#### Linux(APTによるDebian/Ubuntu)```bash
sudo install -d -m 0755 /etc/apt/keyrings
curl -fsSL https://depsguard.com/apt/gpg.key | sudo gpg --dearmor -o /etc/apt/keyrings/depsguard.gpg
echo "deb [arch=amd64,arm64 signed-by=/etc/apt/keyrings/depsguard.gpg] https://depsguard.com/apt stable main" | sudo tee /etc/apt/sources.list.d/depsguard.list >/dev/null
sudo apt update
sudo apt install depsguard

macOS / Linux (Homebrew)```bash

Homebrew

brew install depsguard

DepsGuard は [homebrew-core](https://github.com/Homebrew/homebrew-core/blob/HEAD/Formula/d/depsguard.rb) に含まれているため、カスタム tap は不要です。

> **以前の `arnica/depsguard` tap から移行しますか?** コア formula に一度切り替えてください:
>
> ```bash
> brew uninstall depsguard
> brew untap arnica/depsguard
> brew update
> brew install depsguard
> ```

#### Windows```powershell
# WinGet
winget install Arnica.DepsGuard

# Scoop
scoop bucket add depsguard https://github.com/arnica/depsguard
scoop install depsguard

または、PowerShellを使用して手動でダウンロードします:```powershell $zip = "$env:TEMP\depsguard.zip" Invoke-WebRequest -Uri "https://github.com/arnica/depsguard/releases/latest/download/depsguard-x86_64-pc-windows-msvc.zip" -OutFile $zip Expand-Archive -LiteralPath $zip -DestinationPath "$env:TEMP\depsguard" -Force Copy-Item "$env:TEMP\depsguard\depsguard.exe" "$HOME\AppData\Local\Microsoft\WindowsApps\depsguard.exe" -Force depsguard.exe --help

### crates.io```bash
cargo install depsguard

Rust ツールチェーンと cargo が必要です。

パッケージマネージャー(ベンダーから公開されている場合)

組織が Homebrew、Scoop、または WinGet 経由で DepsGuard を配布している場合は、それぞれの手順に従ってください。これらのチャンネルのセットアップや自動化(Homebrew core の PR、バケット、WinGet の PR、CI シークレット)はメンテナー向けドキュメントです。AGENTS.mdの Release & distribution を参照してください。

アプリストア / パッケージマネージャー

チャンネルLinuxmacOSWindowsインストールコマンド
APT(カスタムリポジトリ)はいいいえいいえsudo apt install depsguard(上記のリポジトリ設定後)
crates.ioはいはいはいcargo install depsguard
Homebrew(homebrew-core)はいはいいいえbrew install depsguard
Scoop(カスタムバケット)いいえいいえはいscoop bucket add depsguard https://github.com/arnica/depsguard ; scoop install depsguard
WinGetいいえいいえはいwinget install Arnica.DepsGuard

最新バージョンへの更新

インストールに使用したチャンネルを使用してください。

チャンネルアップグレードコマンド
Homebrewbrew update && brew upgrade depsguard
APT(カスタムリポジトリ)sudo apt update && sudo apt install --only-upgrade depsguard
crates.iocargo install --force depsguard(最新リリースを再インストール)
Scoopscoop update && scoop update depsguard
WinGetwinget upgrade Arnica.DepsGuard

インストール済みのバージョンはいつでも depsguard --version で確認でき、最新バージョンはリリースページで確認できます。

ソースからビルド```bash

git clone https://github.com/arnica/depsguard.git cd depsguard cargo build --release

バイナリは `target/release/depsguard` (Windows では `.exe`) です。Rust **1.74+** が必要です。

## 使い方```bash
depsguard              # interactive: scan, choose fixes, apply
depsguard scan         # report only; no writes (exits 1 if action is needed)
depsguard --no-search  # skip recursive file search, check local configs only
depsguard restore      # restore from a previous backup
depsguard --help       # CLI help

How to use

  1. インストール – お使いのプラットフォームを上記から選択します。
  2. 実行 – depsguard を実行して対話型 TUI を起動します。システムをスキャンして結果のテーブルを表示します。いずれかのキーを押すと修正セレクタへ進みます。リポジトリレベルの設定の検出は、カレントディレクトリから下方向に検索します。読み取り専用レポートには depsguard scan を使用するか、再帰的なファイル検索をスキップしてユーザーレベルの設定のみを確認するには depsguard --no-search を使用します。

    注: 一部の設定には最低バージョンが必要です。バージョンが古すぎる場合は次のように表示されます: ℹ min-release-age – requires npm ≥ 11.10 (have 10.2.0)。 npm install -g npm@latest でアップグレードして再実行してください。

  3. ナビゲートと選択 – ↑ ↓ でリストを移動し(ページ送りは ^u ^d)、Space で修正のオン/オフを切り替えます。ファイル単位で一括選択するクイックフィルターキー: a すべて、n .npmrc、u uv.toml など – 1回押すと選択、もう1回で選択解除、3回目でフィルターをクリアします。f を押すと現在選択中の修正のみ表示されます。
  4. プレビュー – d を押すと、実際に適用する前に変更内容の差分を確認できます。
  5. 適用 – Enter を押すと選択した修正を適用します。ファイルが書き込まれる前に、タイムスタンプ付きのバックアップが作成されます。
  6. 再スキャン – DepsGuard は適用後に自動でスキャンを再実行するため、すべてが正常であることを確認できます。
  7. 復元 – いつでも depsguard restore を実行して、バックアップ一覧からロールバックできます。q または Esc で終了します。

チェック対象

ツールをダウンロード