DEV Community

Cover image for 617 downloads in a day — dep-inspector-cli v2.2.1 is live, and 2.3.0 is cooking
Nevin-Bali100
Nevin-Bali100

Posted on Originally published at x.com

617 downloads in a day — dep-inspector-cli v2.2.1 is live, and 2.3.0 is cooking

Yesterday I mentioned 250 downloads on X when I launched stable v2.2.1 of my npm package.

Today I opened npm and saw 617 weekly downloads. 🤯🤯🤯
But the craziest part isn't the spike. It's this: v2.0.1, v2.1.0, and v2.2.0 are each still pulling 140+ downloads in the last 7 days. That's not people trying it once — that's pinned in CI caches and mirrors. Real adoption.

So here's what's live, and what's coming.

v2.2.1 — a CI tool, not just a scanner

The theme of this release: scanning is easy, turning a scan into a CI gate is the hard part. v2.2.1 makes every finding-based command CI-ready:

  • --fail-on high|medium|low on every finding-based command
  • Proper exit codes: 1 on threshold breach, 2 on invalid flag
  • 8-worker concurrent version prefetch (dependency tree builds way faster)
  • Container-aware scan:logs (stdout JSON logging in Docker, not file transports)
  • Secret previews are redacted — full secrets never hit your terminal or CI logs
  • .env files committed to git detected via git ls-files, not filename guessing

--fail-on — the one flag that matters

Earlier, failing a build on HIGH findings meant writing node -e hacks that parse JSON in bash. Not anymore.

dep-inspector scan:secrets --fail-on high

🔐 Secrets Scanner

[HIGH] JWT Secret hardcoded
  File : src/middleware/auth.ts:12
  Code : const JWT_SECRET = "my-sup************"

❌ 1 HIGH+ finding(s) — failing with exit code 1
Enter fullscreen mode Exit fullscreen mode

In CI, that's the whole integration — one line.

Exit codes

Code Meaning
0 Clean (or only below-threshold findings)
1 Findings at/above --fail-on threshold
2 Invalid --fail-on level

Redacted by default

One thing that personally bothered me: secret scanners that print the actual secret straight into your terminal. Into CI logs. Into screenshots.

In v2.2.1, every secret preview is redacted before output, and even with the --ai flag, only redacted data goes to Groq. Your secrets never leave your machine in full.

The real problem: legacy repos

A pattern I kept seeing: a team wants to adopt security scanning, but the codebase already has 200 old findings. Fixing all of them takes weeks. So scanning never actually gets adopted.

That's what v2.3.0 solves. Cooking right now:

Baseline mode. Bless the current state once, commit the file, and CI fails only on new findings from that point on.

dep-inspector scan:all --update-baseline
git add .dep-inspector-baseline.json

dep-inspector scan:all --baseline --fail-on high
Enter fullscreen mode Exit fullscreen mode

SHA-256 fingerprints, relative paths (stable across laptop and CI), each scanner gets its own namespace. Old findings acknowledged, new findings blocked.

This is something security tooling hasn't discussed nearly as much as it should. v2.3.0 drops soon.

CI/CD integration

No more node -e hacks. No JSON parsing in bash. One flag.

# .github/workflows/security.yml
name: Security Scan
on: [push, pull_request]

jobs:
  dep-inspector:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - run: npm install -g dep-inspector-cli
      - run: dep-inspector scan:all --baseline --fail-on high
Enter fullscreen mode Exit fullscreen mode

What's next

  • v2.3.0 — baseline mode (in progress, almost there)
  • --format sarif — findings straight into GitHub's Security tab
  • scan:supply — preinstall/postinstall hook audit across node_modules
  • score <package> — dependency trust score before you npm install
  • SBOM export (CycloneDX)

Try it

npm install -g dep-inspector-cli
cd your-project
dep-inspector scan:all
Enter fullscreen mode Exit fullscreen mode
  • 📦 npm:

  • 🐙 GitHub:

    GitHub logo Nevin100 / Dep-inspector-cli

    Version 2 transforms dep-inspector from a dependency analyzer into a full DevOps security toolkit — covering secrets, Docker, CI/CD pipelines, ports, and logging. All features work without any API key. AI insights are optional.

    dep-inspector-cli

    DevOps-grade dependency, security & infrastructure scanner for Node.js projects.

    npm version npm downloads License: MIT TypeScript PRs Welcome


    What's new in v2

    Version 2 transforms dep-inspector from a dependency analyzer into a full DevOps security toolkit — covering secrets, Docker, CI/CD pipelines, ports, and logging. All features work without any API key. AI insights are optional.

    • v2.2.1 — --fail-on high|medium|low exit codes on every finding-based command.

    Features






































    Command What it does
    dep-inspector Dependency tree + vulnerability scan (v1)
    scan:secrets Detect hardcoded API keys, .env leaks, private keys
    scan:docker Dockerfile security analysis
    scan:ci GitHub Actions workflow linting
    scan:ports Open port detection & process monitoring
    scan:logs Winston/Morgan/Pino logger health check
    scan:all Run everything, one report, one exit code


    Installation

    npm install -g dep-inspector-cli
    Enter fullscreen mode Exit fullscreen mode

    Usage

    Dependency Analysis (v1)

    dep-inspector                   # Full analysis
    dep-inspector analyze           # Same, explicit subcommand
    dep-inspector --depth 3         # Limit tree depth
    dep-inspector --json            # Machine-readable output
    dep-inspector --ai              # AI-powered insights (optional, needs GROQ_API_KEY)
    Enter fullscreen mode Exit fullscreen mode

    Security Scans

    …

If it's useful, a ⭐ on GitHub helps a lot. Issues and PRs are open.

Top comments (0)