open source · MIT · zero-dependency CLI

Supply-chain security
for your dependencies.

Chainlock matches your lockfiles against the OSV vulnerability database, scores supply-chain risk per package, flags typosquats and exports an SBOM — locally and in CI.

pip install chainlock-cli · Python · npm · Go lockfiles

chainlock scan requirements.txt
chainlock scan requirements.txt Querying OSV database for 6 deps... RISK PACKAGE VERSION FINDINGS CRITICAL flask 2.0.0 4 advisories · unpinned HIGH requests 2.19.0 10 advisories GHSA-9hjg HIGH urllib3 1.24.0 26 advisories MEDIUM reqeusts 0.0.8 typosquat of 'requests' LOW rich 13.7.0 clean LOW sqlalchemy 1.3.0 clean Summary: 3 of 6 dependencies vulnerable 1 critical · 2 high · 1 medium · 2 low Data: OSV (osv.dev) · exit code 1

Everything a supply-chain check should be

No agents, no sidecars, no dependency tree of its own. One binary-minded CLI you can read in an afternoon.

OSV-powered scanning

Batch queries against Google's OSV.dev database across PyPI, npm and Go — advisories, CVEs and fix versions.

Typosquat detection

Edit-distance matching against curated lists of the most-imitated package names — catch reqeusts before it ships.

Risk scoring

Every dependency gets a 0–100 score from advisory severity, fix availability, pinning discipline and typosquat signals.

CycloneDX SBOM

--sbom sbom.json emits a CycloneDX 1.5 bill of materials with purls — ready for your compliance pipeline.

Zero dependencies

The tool auditing your supply chain never adds to it. Python stdlib only — pip install and you're done.

CI-native exit codes

Non-zero exit on HIGH/CRITICAL findings makes any pipeline a policy gate. One line in GitHub Actions.

Up and running in 60 seconds

Works with requirements.txt, package-lock.json and go.sum.

Install

One package, no transitive deps.

pip install chainlock-cli

Scan

Point it at any supported lockfile.

chainlock scan requirements.txt \
  --sbom sbom.json

Enforce

Gate your CI on the exit code.

- run: chainlock scan package-lock.json
Chainlock Cloud · early access

The CLI is open source. The platform is coming.

Chainlock Cloud turns one-off scans into continuous supply-chain posture for your whole organization.

Org dashboardEvery repo and CI run in one place, with diff-aware alerts on new findings.
Policy engineBlock typosquats, unpinned versions or license drift at pull-request time.
Continuous monitoringRe-alert when a new advisory lands on a version you already shipped.
Request early access