Skip to content

qwexvf/aegis-cli

CLI & Terminal

Supply‑chain security scanner that checks CVEs, secret leaks, AST patterns and policy compliance across 16 package ecosystems without needing an account or backend

Go Latest v0.29.1 · 1mo ago Security brief →

Features

  • Batch CVE/GHSA lookup for 16 ecosystems with `FixedIn` version info via OSV.dev
  • AST‑based capability scan detecting dangerous functions (shell spawn, network egress, dynamic eval, file writes outside root)
  • Taint analysis revealing obfuscated C2 hostnames and indirect `eval` chains
  • Hardcoded secret detection for AWS, GitHub, npm, Stripe, Slack tokens etc. in dependency source code
  • GitHub Actions workflow scanning for unpinned actions, privilege escalation patterns and script injection

Recent releases

View all 31 releases →
Review required
v0.29.1 Maintenance
Dependencies

Dep updates

No immediate action
v0.29.0 Mixed

Suppression gap fix + Go 1.26.4

Review required
v0.28.0 New feature
Dependencies

@qwexvf CLI, registry, AST, heuristics, docs

No immediate action
v0.27.0 New feature

SBOM + Lua AST scanner

No immediate action
v0.26.0 New feature

AST scan + lockfile extraction

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
2
Forks
0
Languages
Go TypeScript Astro

Install & Platforms

Install via
go

Beta — feedback welcome: [email protected]