Stale deps, CVEs and end-of-life, on one page.
Scan a repo, get three numbers: libyears behind, known CVEs, and how soon something reaches end-of-life.
deeps-scan --dir ./whngo --format markdown
- libyears
- 6.71
- CVEs
- 0
- end-of-life
- 0
- dependencies
- 14
| Dependency | Installed | Latest | Libyears |
|---|---|---|---|
| github.com/dustin/go-humanize | 1.0.1 | 1.1.0 | 3.69 |
| github.com/stretchr/testify | 1.11.1 | 1.12.1 | 0.97 |
| go.etcd.io/bbolt | 1.4.3 | 1.5.0 | 0.79 |
| github.com/tdewolff/minify/v2 | 2.24.13 | 2.24.17 | 0.30 |
| golang.org/x/sys | 0.46.0 | 0.48.0 | 0.26 |
A scanner for engineers, not a compliance report
Most scanners produce compliance evidence for security teams. Deeps is for engineers cutting tech debt. The CLI fits one screen, the report fits one PR comment, and the dashboard tracks libyears over time. Hosting is optional: the scanner runs offline and uploads only when you ask it to.
- Libyears
- Every dependency's age, measured against its latest release. One score per package, summed per project. Sort the table to find the worst debt first.
- CVEs that matter
- Trivy finds them; Deeps sorts by severity, filters to the ones with a fix, and links straight to it. No 50-line descriptions to scroll past.
- End-of-life detection
- Reads your Dockerfile, package.json, go.mod, and composer.json, then checks endoflife.date. Tells you “Node 16 ends in 38 days” before it breaks in prod.
- Notifications
- Web push, email, APNs, FCM. Per project, per severity. Digest or realtime.
The same scan everywhere
The hosted dashboard runs the same pipeline as the CLI. Point it at any directory:
deeps-scan --dir . \
--severity-floor high \
--max-libyears 100 \
--format markdownWhere Deeps runs
- CLI
- A single Go binary. Run it against any directory and get JSON, Markdown, SARIF, or KPI slides on stdout.
- Docker image
- Trivy bundled, runs nonroot, about 80 MB. The base artefact every CI integration wraps.
- GitHub Action
- A drop-in workflow step. Forgejo Actions uses the same action.yml unchanged.
- GitLab CI template
- Include it from your .gitlab-ci.yml. Posts the Markdown report as an MR note.
- Hosted dashboard
- Optional, coming soon. Cross-project library, scan history, libyears trends, and APIs an agent can call.
Run your first scan
Grab the CLI and run it against any repo. The hosted dashboard is on the way.