Scan agent dependencies and container inputs with OWASP dep-scan
Run OWASP dep-scan before adopting dependencies, containers, or generated code so agents get a reviewable vulnerability, license, SBOM, and risk report.
Prerequisites
Python, pip, OWASP dep-scan, optional CycloneDX cdxgen, Docker for container-image scans, CI runner or local shell
Installation
Use the upstream install or setup path that matches your environment:
- pip install owasp-depscan
- pip install owasp-depscan[all]
- docker save -o /tmp/scanslim.tar shiftleft/scan-slim:latest
- docker run --rm -v $PWD:/app ghcr.io/owasp-dep-scan/dep-scan depscan --src /app --reports-dir /app/reports
Requirements and caveats from upstream:
- Scanning projects locally (Python version)
- Scanning containers locally (Python version)
- Scanning projects locally (Docker container)
Basic usage or getting-started notes:
Extracted from upstream docs: https://raw.githubusercontent.com/owasp-dep-scan/dep-scan/HEAD/README.md