
サプライチェーン攻撃に対してパッケージマネージャーの設定を強化します。
```text
_ _
| | ___ _ __ ___ __ _ _ _ __ _ _ __ | |
/
|/ _ \ '_ \/ __|/ _ | | | |/ | '__/ _ |
| (| | __/ |) _ \ (| | || | (| | | | (| |
_,_|_| ./|/_, |_,|_,|| _,|
|| |___/
Guard your dependencies against supply chain attacks. **Single static binary, zero Rust crate dependencies.**
作者 **[[arnica](https://arnica.io?utm_source=depsguard&utm_medium=referral&utm_campaign=community)]**
## Table of contents
- [概要](#overview)
- [インストール](#install)
- [使い方](#usage)
- [チェックされる内容](#what-gets-checked)
- [設定ファイルの場所](#config-file-locations)
- [緊急セキュリティ修正](#urgent-security-fix)
- [バックアップと復元](#backups-and-restore)
- [仕組み](#how-it-works)
- [トラブルシューティング](#troubleshooting)
- [ヘルプとフィードバック](#help--feedback)
- [ガイド](#guides)
- [関連項目](#see-also)
- [ライセンス](#license)
## 概要
DepsGuardは、お使いのマシン上の**npm**、**pnpm**、**yarn**、**bun**、**uv**、**pip**、**poetry**、**aube**を検出し、それらの設定ファイルを読み取り、推奨されるサプライチェーン設定と比較して、**修正を対話的に適用**できます。また、リポジトリ内の**Renovate**および**Dependabot**の設定もスキャンします。パッケージのインストールは一切実行しません。承認した設定ファイルのみを編集し、変更前には常に**バックアップ**を作成します。
### 主な機能
- 対話型TUI:スキャン、レビュー、修正の切り替え、適用
- 読み取り専用レポート用の`scan`サブコマンド
- バックアップを選択してファイルをロールバックするための`restore`サブコマンド
- クロスプラットフォーム:Linux、macOS、Windows
- サードパーティのRustクレートを同梱しない(標準ライブラリ+端末用の少量のプラットフォームFFI)
### 技術スタック
| 分野 | 詳細 |
|------|---------|
| 言語 | Rust(MSRV **1.74**、`Cargo.toml`を参照) |
| CLI / TUI | `src/main.rs`, `src/ui.rs`, `src/term.rs` |
| 設定ロジック | `src/manager.rs`, `src/fix.rs` |
| Webサイト | `docs/` 配下の静的サイト(バイナリとは別) |
## インストール
### プリビルトバイナリ
各[GitHub Release](https://github.com/arnica/depsguard/releases)には、次のアーカイブが含まれています:
- Linux: `x86_64` (glibc), `x86_64` (musl), `aarch64` (glibc)
- macOS: IntelおよびApple Silicon
- Windows: `x86_64` ZIP(`depsguard.exe`を含む)
お使いのプラットフォームのアーカイブをダウンロードし、解凍して、`PATH`にバイナリを配置してください。
リリースページで各アセットの隣にある対応する`.sha256`ファイルを使用して整合性を検証してください。
### プラットフォーム別のインストール
#### Linux(APTによるDebian/Ubuntu)```bash
sudo install -d -m 0755 /etc/apt/keyrings
curl -fsSL https://depsguard.com/apt/gpg.key | sudo gpg --dearmor -o /etc/apt/keyrings/depsguard.gpg
echo "deb [arch=amd64,arm64 signed-by=/etc/apt/keyrings/depsguard.gpg] https://depsguard.com/apt stable main" | sudo tee /etc/apt/sources.list.d/depsguard.list >/dev/null
sudo apt update
sudo apt install depsguard
brew install depsguard
DepsGuard は [homebrew-core](https://github.com/Homebrew/homebrew-core/blob/HEAD/Formula/d/depsguard.rb) に含まれているため、カスタム tap は不要です。
> **以前の `arnica/depsguard` tap から移行しますか?** コア formula に一度切り替えてください:
>
> ```bash
> brew uninstall depsguard
> brew untap arnica/depsguard
> brew update
> brew install depsguard
> ```
#### Windows```powershell
# WinGet
winget install Arnica.DepsGuard
# Scoop
scoop bucket add depsguard https://github.com/arnica/depsguard
scoop install depsguard
または、PowerShellを使用して手動でダウンロードします:```powershell $zip = "$env:TEMP\depsguard.zip" Invoke-WebRequest -Uri "https://github.com/arnica/depsguard/releases/latest/download/depsguard-x86_64-pc-windows-msvc.zip" -OutFile $zip Expand-Archive -LiteralPath $zip -DestinationPath "$env:TEMP\depsguard" -Force Copy-Item "$env:TEMP\depsguard\depsguard.exe" "$HOME\AppData\Local\Microsoft\WindowsApps\depsguard.exe" -Force depsguard.exe --help
### crates.io```bash
cargo install depsguard
Rust ツールチェーンと cargo が必要です。
組織が Homebrew、Scoop、または WinGet 経由で DepsGuard を配布している場合は、それぞれの手順に従ってください。これらのチャンネルのセットアップや自動化(Homebrew core の PR、バケット、WinGet の PR、CI シークレット)はメンテナー向けドキュメントです。AGENTS.mdの Release & distribution を参照してください。
| チャンネル | Linux | macOS | Windows | インストールコマンド |
|---|---|---|---|---|
| APT(カスタムリポジトリ) | はい | いいえ | いいえ | sudo apt install depsguard(上記のリポジトリ設定後) |
| crates.io | はい | はい | はい | cargo install depsguard |
| Homebrew(homebrew-core) | はい | はい | いいえ | brew install depsguard |
| Scoop(カスタムバケット) | いいえ | いいえ | はい | scoop bucket add depsguard https://github.com/arnica/depsguard ; scoop install depsguard |
| WinGet | いいえ | いいえ | はい | winget install Arnica.DepsGuard |
インストールに使用したチャンネルを使用してください。
| チャンネル | アップグレードコマンド |
|---|---|
| Homebrew | brew update && brew upgrade depsguard |
| APT(カスタムリポジトリ) | sudo apt update && sudo apt install --only-upgrade depsguard |
| crates.io | cargo install --force depsguard(最新リリースを再インストール) |
| Scoop | scoop update && scoop update depsguard |
| WinGet | winget upgrade Arnica.DepsGuard |
インストール済みのバージョンはいつでも depsguard --version で確認でき、最新バージョンはリリースページで確認できます。
git clone https://github.com/arnica/depsguard.git cd depsguard cargo build --release
バイナリは `target/release/depsguard` (Windows では `.exe`) です。Rust **1.74+** が必要です。
## 使い方```bash
depsguard # interactive: scan, choose fixes, apply
depsguard scan # report only; no writes (exits 1 if action is needed)
depsguard --no-search # skip recursive file search, check local configs only
depsguard restore # restore from a previous backup
depsguard --help # CLI help
depsguard を実行して対話型 TUI を起動します。システムをスキャンして結果のテーブルを表示します。いずれかのキーを押すと修正セレクタへ進みます。リポジトリレベルの設定の検出は、カレントディレクトリから下方向に検索します。読み取り専用レポートには depsguard scan を使用するか、再帰的なファイル検索をスキップしてユーザーレベルの設定のみを確認するには depsguard --no-search を使用します。
注: 一部の設定には最低バージョンが必要です。バージョンが古すぎる場合は次のように表示されます:
ℹ min-release-age – requires npm ≥ 11.10 (have 10.2.0)。npm install -g npm@latestでアップグレードして再実行してください。
↑ ↓ でリストを移動し(ページ送りは ^u ^d)、Space で修正のオン/オフを切り替えます。ファイル単位で一括選択するクイックフィルターキー: a すべて、n .npmrc、u uv.toml など – 1回押すと選択、もう1回で選択解除、3回目でフィルターをクリアします。f を押すと現在選択中の修正のみ表示されます。d を押すと、実際に適用する前に変更内容の差分を確認できます。Enter を押すと選択した修正を適用します。ファイルが書き込まれる前に、タイムスタンプ付きのバックアップが作成されます。depsguard restore を実行して、バックアップ一覧からロールバックできます。q または Esc で終了します。