Scan project dependencies for supply-chain vulnerabilities with MurphySec
Run MurphySec CLI against a project before release or dependency approval to detect vulnerable direct and transitive dependencies.
Prerequisites
MurphySec CLI; MurphySec account access token for authentication
Installation
Requirements and caveats from upstream:
- MurphySec CLI requires an access token from your MurphySec account for authentication to work properly. What is an access token?
- --log-level string specify log level, must be silent|error|warn|info|debug
Basic usage or getting-started notes:
Visit the GitHub Releases page to download the latest version of MurphySec CLI, or install it by running:
wget -q https://s.murphysec.com/release/install.sh -O - | /bin/bash
Extracted from upstream docs: https://raw.githubusercontent.com/murphysecurity/murphysec/HEAD/README.md