Catch vulnerable npm dependencies before they ship. DepGuard scans package.json in real time — including the full transitive tree — against the OSV.dev vulnerability database.
Installation
Launch VS Code Quick Open (Ctrl+P), paste the following command, and press enter.
Real-time, shift-left dependency vulnerability scanning for package.json, powered by OSV.dev.
Detects vulnerabilities in both direct dependencies and every transitive package installed under them, and attributes the risk back to the top-level entry in package.json that owns it.
Features
🛡️ Inline diagnostics on the exact version string of each vulnerable dependency
🔗 Deep scanning of the entire installed tree via npm ls --all --json
🧭 Transitive vulnerabilities surfaced on the direct dep that pulls them in, with the full dependency path
💡 Quick-fix upgrade action for direct-dep vulnerabilities
🖱️ Rich hover cards with CVE ids, severity, aliases and OSV.dev links
⚡ LRU-cached OSV batch queries and lockfile-keyed dep-tree cache
Requirements
Node.js and npm available on PATH (used to gather the installed dep tree)
Project must have run npm install at least once so npm ls can resolve versions
Upgrading from an older version? Any custom values you'd set under the old fmd.* settings are copied over to depguard.* automatically the first time you activate this version — no action needed.
Commands
DepGuard: Show Logs — reveal the extension output channel
DepGuard: Rescan Active package.json — force a fresh scan and drop the cached dep tree