GitHub Dependency Checker
Enter a public GitHub repository URL. We'll automatically fetch its dependencies and scan them against the OSV database for known vulnerabilities.
How This Tool Works
Fetch Repository Files
We securely fetch supported dependency files (package.json, requirements.txt, pom.xml, composer.json) from the repository's default branch.
Parse Dependencies
The tool extracts the exact dependency names and standardizes the versions (e.g. stripping modifiers like ^ and ~) across all supported ecosystems.
Vulnerability OSV Scan
We send the parsed list to the public Open Source Vulnerabilities (OSV) API, identifying known CVEs, summaries, and references.
About GitHub Dependency Checker
Scan GitHub repositories for dependencies and their versions to ensure security and up-to-date packages.
Why use this checker?
Our tools are designed to be fast, free, and fully client-side. This means your data never leaves your browser, ensuring maximum privacy and security. Simply interact with the interface above to get instant results without any server delays.