Yesterday I mentioned 250 downloads on X when I launched stable v2.2.1 of my npm package.
Today I opened npm and saw 617 weekly downloads. 🤯🤯🤯
But the craziest part isn't the spike. It's this: v2.0.1, v2.1.0, and v2.2.0 are each still pulling 140+ downloads in the last 7 days. That's not people trying it once — that's pinned in CI caches and mirrors. Real adoption.
So here's what's live, and what's coming.
v2.2.1 — a CI tool, not just a scanner
The theme of this release: scanning is easy, turning a scan into a CI gate is the hard part. v2.2.1 makes every finding-based command CI-ready:
-
--fail-on high|medium|lowon every finding-based command - Proper exit codes:
1on threshold breach,2on invalid flag - 8-worker concurrent version prefetch (dependency tree builds way faster)
- Container-aware
scan:logs(stdout JSON logging in Docker, not file transports) - Secret previews are redacted — full secrets never hit your terminal or CI logs
-
.envfiles committed to git detected viagit ls-files, not filename guessing
--fail-on — the one flag that matters
Earlier, failing a build on HIGH findings meant writing node -e hacks that parse JSON in bash. Not anymore.
dep-inspector scan:secrets --fail-on high
🔐 Secrets Scanner
[HIGH] JWT Secret hardcoded
File : src/middleware/auth.ts:12
Code : const JWT_SECRET = "my-sup************"
❌ 1 HIGH+ finding(s) — failing with exit code 1
In CI, that's the whole integration — one line.
Exit codes
| Code | Meaning |
|---|---|
| 0 | Clean (or only below-threshold findings) |
| 1 | Findings at/above --fail-on threshold |
| 2 | Invalid --fail-on level |
Redacted by default
One thing that personally bothered me: secret scanners that print the actual secret straight into your terminal. Into CI logs. Into screenshots.
In v2.2.1, every secret preview is redacted before output, and even with the --ai flag, only redacted data goes to Groq. Your secrets never leave your machine in full.
The real problem: legacy repos
A pattern I kept seeing: a team wants to adopt security scanning, but the codebase already has 200 old findings. Fixing all of them takes weeks. So scanning never actually gets adopted.
That's what v2.3.0 solves. Cooking right now:
Baseline mode. Bless the current state once, commit the file, and CI fails only on new findings from that point on.
dep-inspector scan:all --update-baseline
git add .dep-inspector-baseline.json
dep-inspector scan:all --baseline --fail-on high
SHA-256 fingerprints, relative paths (stable across laptop and CI), each scanner gets its own namespace. Old findings acknowledged, new findings blocked.
This is something security tooling hasn't discussed nearly as much as it should. v2.3.0 drops soon.
CI/CD integration
No more node -e hacks. No JSON parsing in bash. One flag.
# .github/workflows/security.yml
name: Security Scan
on: [push, pull_request]
jobs:
dep-inspector:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- run: npm install -g dep-inspector-cli
- run: dep-inspector scan:all --baseline --fail-on high
What's next
- v2.3.0 — baseline mode (in progress, almost there)
-
--format sarif— findings straight into GitHub's Security tab -
scan:supply— preinstall/postinstall hook audit across node_modules -
score <package>— dependency trust score before younpm install - SBOM export (CycloneDX)
Try it
npm install -g dep-inspector-cli
cd your-project
dep-inspector scan:all
-
📦 npm:
-
🐙 GitHub:
Nevin100 / Dep-inspector-cli
Version 2 transforms dep-inspector from a dependency analyzer into a full DevOps security toolkit — covering secrets, Docker, CI/CD pipelines, ports, and logging. All features work without any API key. AI insights are optional.
dep-inspector-cli
DevOps-grade dependency, security & infrastructure scanner for Node.js projects.
What's new in v2
Version 2 transforms
dep-inspectorfrom a dependency analyzer into a full DevOps security toolkit — covering secrets, Docker, CI/CD pipelines, ports, and logging. All features work without any API key. AI insights are optional.-
v2.2.1 —
--fail-on high|medium|lowexit codes on every finding-based command.
Features
Command
What it does
dep-inspector
Dependency tree + vulnerability scan (v1)
scan:secrets
Detect hardcoded API keys, .env leaks, private keys
scan:docker
Dockerfile security analysis
scan:ci
GitHub Actions workflow linting
scan:ports
Open port detection & process monitoring
scan:logs
Winston/Morgan/Pino logger health check
scan:all
Run everything, one report, one exit code
Installation
npm install -g dep-inspector-cli
Usage
Dependency Analysis (v1)
dep-inspector # Full analysis dep-inspector analyze # Same, explicit subcommand dep-inspector --depth 3 # Limit tree depth dep-inspector --json # Machine-readable output dep-inspector --ai # AI-powered insights (optional, needs GROQ_API_KEY)
Security Scans
… -
v2.2.1 —
If it's useful, a ⭐ on GitHub helps a lot. Issues and PRs are open.
Top comments (0)