Chainlock matches your lockfiles against the OSV vulnerability database, scores supply-chain risk per package, flags typosquats and exports an SBOM — locally and in CI.
No agents, no sidecars, no dependency tree of its own. One binary-minded CLI you can read in an afternoon.
Batch queries against Google's OSV.dev database across PyPI, npm and Go — advisories, CVEs and fix versions.
Edit-distance matching against curated lists of the most-imitated package names — catch reqeusts before it ships.
Every dependency gets a 0–100 score from advisory severity, fix availability, pinning discipline and typosquat signals.
--sbom sbom.json emits a CycloneDX 1.5 bill of materials with purls — ready for your compliance pipeline.
The tool auditing your supply chain never adds to it. Python stdlib only — pip install and you're done.
Non-zero exit on HIGH/CRITICAL findings makes any pipeline a policy gate. One line in GitHub Actions.
Works with requirements.txt, package-lock.json and go.sum.
One package, no transitive deps.
pip install chainlock-cli
Point it at any supported lockfile.
chainlock scan requirements.txt \ --sbom sbom.json
Gate your CI on the exit code.
- run: chainlock scan package-lock.json
Chainlock Cloud turns one-off scans into continuous supply-chain posture for your whole organization.