Depth-aware scoring
We don't dump 1,400 vulns at the same severity. The score blends CVE severity and dependency depth — so direct, critical issues surface above deep transitives.
§01 Software supply-chain triage
Drop a lockfile, get a prioritized risk report and a CycloneDX SBOM in 30 seconds. No account, no CLI, no lockfile ever written to disk.
Drop your lockfile here
or tap to browse — parsed in memory, never written to disk.
package-lock.json · yarn.lock · requirements.txt · go.sum · Pipfile.lock — max 5 MB
| Risk | Package | Version | Ecosystem | Depth | CVEs | Max severity |
|---|
Lockfile parsed in memory · never written to disk · deleted after scoring
§03 How it works
package-lock.json, yarn.lock, requirements.txt, go.sum, Pipfile.lock — sent over HTTPS, parsed in memory, never written to disk.
Each package scored by CVE severity, count, and dependency depth. Critical issues and direct dependencies surface at the top — not buried in 1,400 entries.
Download a CycloneDX 1.5 JSON SBOM to attach to your EU CRA, FedRAMP or SOC 2 evidence pack — or a CSV triage list to share with the team. Output is informational; you remain responsible for compliance.
§04 Why DepTriage
We don't dump 1,400 vulns at the same severity. The score blends CVE severity and dependency depth — so direct, critical issues surface above deep transitives.
Export CycloneDX 1.5 JSON. Designed for the EU Cyber Resilience Act, US EO 14028 and SOC 2 evidence packs — drop it straight in your audit folder.
Your file is parsed in memory and discarded after scoring. No accounts, no logs, no disk writes — just the report.
No CLI to install, no GitHub app to authorize, no enterprise sales call. Paste the lockfile and you have an answer before your coffee cools.
§05 Questions
package-lock.json (npm), yarn.lock, pnpm-lock.yaml, requirements.txt (Python), Pipfile.lock and go.sum.§06 Pricing
Payments processed securely by Stripe. We never store card details.