Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
depsguard — 加固你的包管理器配置以抵御供应链攻击。 | Kitploit
工具/GitHubGitHub/arnica/depsguard
漏洞分析配置审计云安全DevSecOps秘密检测供应链安全
GitHubarnica/depsguard

depsguard

加固你的包管理器配置以抵御供应链攻击。

查看仓库
38218182个月前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
网站
分享

depsguard

CI Security Audit crates.io License: MIT MSRV```text _ _ | | ___ _ __ ___ __ _ _ _ __ _ _ __ | | / |/ _ \ '_ \/ __|/ _ | | | |/ | '__/ _ | | (| | __/ |) _ \ (| | || | (| | | | (| | _,_|_| ./|/_, |_,|_,|| _,| || |___/

保护你的依赖项免受供应链攻击。**单个静态二进制文件,零 Rust crate 依赖。**

由 **[[arnica](https://arnica.io?utm_source=depsguard&utm_medium=referral&utm_campaign=community)]**

## 目录

- [概述](#overview)
- [安装](#install)
- [使用](#usage)
- [检查内容](#what-gets-checked)
- [配置文件位置](#config-file-locations)
- [紧急安全修复](#urgent-security-fix)
- [备份与恢复](#backups-and-restore)
- [工作原理](#how-it-works)
- [故障排除](#troubleshooting)
- [帮助与反馈](#help--feedback)
- [指南](#guides)
- [另请参阅](#see-also)
- [许可证](#license)

## 概述

DepsGuard 会在你的机器上查找 **npm**、**pnpm**、**yarn**、**bun**、**uv**、**pip**、**poetry** 和 **aube**,读取它们的配置文件,将其与推荐的供应链设置进行比较,并可以**交互式应用修复**。它还会扫描你仓库中的 **Renovate** 和 **Dependabot** 配置。它从不运行包安装;它只编辑你批准的配置文件,并且在任何更改前都会写入**备份**。

### 主要特性

- 交互式 TUI:扫描、审查、切换修复、应用
- `scan` 子命令用于只读报告
- `restore` 子命令用于选择备份并回滚文件
- 跨平台:Linux、macOS、Windows
- 无捆绑的第三方 Rust crate(标准库 + 少量用于终端的平台 FFI)

### 技术栈

| 领域 | 详情 |
|------|---------|
| 语言 | Rust(MSRV **1.74**,见 `Cargo.toml`) |
| CLI / TUI | `src/main.rs`、`src/ui.rs`、`src/term.rs` |
| 配置逻辑 | `src/manager.rs`、`src/fix.rs` |
| 网站 | `docs/` 下的静态站点(与二进制文件分开) |

## 安装

### 预构建二进制文件

每个 [GitHub Release](https://github.com/arnica/depsguard/releases) 包含以下平台的归档:

- Linux:`x86_64`(glibc)、`x86_64`(musl)、`aarch64`(glibc)
- macOS:Intel 和 Apple Silicon
- Windows:包含 `depsguard.exe` 的 `x86_64` ZIP

下载你平台的归档,解压,并将二进制文件放入你的 `PATH` 中。

使用发布页面上每个资产旁边的匹配 `.sha256` 文件验证完整性。

### 按平台安装

#### Linux(通过 APT 在 Debian/Ubuntu 上)```bash
sudo install -d -m 0755 /etc/apt/keyrings
curl -fsSL https://depsguard.com/apt/gpg.key | sudo gpg --dearmor -o /etc/apt/keyrings/depsguard.gpg
echo "deb [arch=amd64,arm64 signed-by=/etc/apt/keyrings/depsguard.gpg] https://depsguard.com/apt stable main" | sudo tee /etc/apt/sources.list.d/depsguard.list >/dev/null
sudo apt update
sudo apt install depsguard

macOS / Linux (Homebrew)```bash

Homebrew

brew install depsguard

DepsGuard 已在 [homebrew-core](https://github.com/Homebrew/homebrew-core/blob/HEAD/Formula/d/depsguard.rb) 中,因此无需自定义 tap。

> **从旧的 `arnica/depsguard` tap 迁移?** 请切换到 core 公式:
>
> ```bash
> brew uninstall depsguard
> brew untap arnica/depsguard
> brew update
> brew install depsguard
> ```

#### Windows```powershell
# WinGet
winget install Arnica.DepsGuard

# Scoop
scoop bucket add depsguard https://github.com/arnica/depsguard
scoop install depsguard

或者通过 PowerShell 手动下载:```powershell $zip = "$env:TEMP\depsguard.zip" Invoke-WebRequest -Uri "https://github.com/arnica/depsguard/releases/latest/download/depsguard-x86_64-pc-windows-msvc.zip" -OutFile $zip Expand-Archive -LiteralPath $zip -DestinationPath "$env:TEMP\depsguard" -Force Copy-Item "$env:TEMP\depsguard\depsguard.exe" "$HOME\AppData\Local\Microsoft\WindowsApps\depsguard.exe" -Force depsguard.exe --help

### crates.io```bash
cargo install depsguard

需要一个安装了 cargo 的 Rust 工具链。

包管理器(由你的供应商发布时)

如果你的组织通过 Homebrew、Scoop 或 WinGet 分发 DepsGuard,请使用它们的说明。设置或自动化这些渠道(Homebrew core PRs、buckets、WinGet PRs、CI secrets)属于维护者文档;请参阅 AGENTS.md 中的 发布与分发 部分。

应用商店 / 包管理器

渠道LinuxmacOSWindows安装命令
APT(自定义仓库)yesnonosudo apt install depsguard(完成上述仓库设置后)
crates.ioyesyesyescargo install depsguard
Homebrew(homebrew-core)yesyesnobrew install depsguard
Scoop(自定义 bucket)nonoyesscoop bucket add depsguard https://github.com/arnica/depsguard ; scoop install depsguard
WinGetnonoyeswinget install Arnica.DepsGuard

更新到最新版本

使用你安装时所用的渠道:

渠道升级命令
Homebrewbrew update && brew upgrade depsguard
APT(自定义仓库)sudo apt update && sudo apt install --only-upgrade depsguard
crates.iocargo install --force depsguard(重新安装最新版本)
Scoopscoop update && scoop update depsguard
WinGetwinget upgrade Arnica.DepsGuard

随时使用 depsguard --version 检查已安装的版本,并查看发布页面以获取最新版本。

从源码构建```bash

git clone https://github.com/arnica/depsguard.git cd depsguard cargo build --release

二进制文件位于 `target/release/depsguard`(Windows 上为 `.exe`)。需要 Rust **1.74+**。

## 用法```bash
depsguard              # interactive: scan, choose fixes, apply
depsguard scan         # report only; no writes (exits 1 if action is needed)
depsguard --no-search  # skip recursive file search, check local configs only
depsguard restore      # restore from a previous backup
depsguard --help       # CLI help

使用方法

  1. 安装 – 选择您的平台 如上。
  2. 运行 depsguard 以启动交互式 TUI。它会扫描您的系统并显示一份结果表格。按任意键继续进入修复选择器。仓库级配置发现从当前目录开始向下搜索。使用 depsguard scan 可生成只读报告,或使用 depsguard --no-search 跳过递归文件搜索,仅检查用户级配置。

    注意: 某些设置需要最低版本。如果您的版本过旧,您将看到: ℹ min-release-age – 需要 npm ≥ 11.10(当前为 10.2.0)。 使用 npm install -g npm@latest 升级并重新运行。

  3. 导航与选择 – 使用 ↑ ↓ 在列表中移动(^u ^d 翻页)。按 Space 切换修复的开关状态。使用快速过滤键按文件批量选择:a 全部,n .npmrc,u uv.toml 等——按一次选择,再按一次取消选择,第三次清除过滤。按 f 仅显示当前选中的修复。
  4. 预览 – 按 d 查看将会变更的差异(diff),确认无误后再执行。
  5. 应用 – 按 Enter 应用选中的修复。写入任何文件前都会创建带时间戳的备份。
  6. 重新扫描 – DepsGuard 会在应用后自动重新运行扫描,以便您验证一切已变绿。
  7. 恢复 – 随时运行 depsguard restore 从备份列表中回滚。按 q 或 Esc 退出。

检查内容

下载工具