Verisight Help Center Support ticket Open portal

Supply Chain Check

Find malicious and vulnerable open-source packages in your npm, Composer and Python projects.

The Supply Chain Check reads the dependency files of your projects and tells you which packages are known-malicious or vulnerable, and what to upgrade to.

Supported files

Ecosystem Lockfiles (exact versions) Manifests (version ranges)
npm / JavaScript package-lock.json, yarn.lock, pnpm-lock.yaml package.json
Composer / PHP composer.lock composer.json
Python poetry.lock, uv.lock, Pipfile.lock, pinned requirements*.txt requirements*.txt

Upload lockfiles whenever you can. With only a manifest the versions aren't exact. Malicious packages are still detected, but version-specific vulnerabilities can't be, and the result says coverage is partial. Files are limited to 5 MiB and 20,000 packages each.

How to run it

  1. Open Settings → Software and upload your files. Group a manifest with its lockfile under the same project name.
  2. Open Assessment Products → Supply Chain Check and select the files to check.
  3. Place the order. The check starts straight away; no authorisation is needed, because nothing of yours is scanned.

What you get

  • One critical finding per malicious package, with instructions to remove it and rotate any secrets the package could have reached (CI, developer machines).
  • One finding per vulnerable package (not one per CVE), with the lowest version that fixes every advisory.
  • Risk signals: install scripts, packages from git or URLs instead of the registry, private packages that couldn't be checked, missing integrity hashes, manifests without a lockfile.

If the advisory lookup fails, you get an incomplete result, never a false "all clear".

Your code stays private

  • Files are parsed as data and then discarded. Only the package list, the file name and its checksum are kept.
  • Only public package names and versions are looked up, against OSV.dev and the OpenSSF malicious-packages feed.
  • Packages from a private registry, git or a local path are never sent anywhere. Their names could be confidential.

After the check, keep the files in Software: Stack Watch goes on watching them every day.

Price

€149 standalone, €129 on Essentials. Included 1× per quarter on Managed and per month on vCISO.