Skip to content
| Marketplace
Sign in
Visual Studio Code>Linters>DepGuard - Real-Time OSV Dependency Vulnerability ScannerNew to Visual Studio Code? Get it now.
DepGuard - Real-Time OSV Dependency Vulnerability Scanner

DepGuard - Real-Time OSV Dependency Vulnerability Scanner

Fatih Mahmut Dundar

|
7 installs
| (0) | Free
Catch vulnerable npm dependencies before they ship. DepGuard scans package.json in real time — including the full transitive tree — against the OSV.dev vulnerability database.
Installation
Launch VS Code Quick Open (Ctrl+P), paste the following command, and press enter.
Copied to clipboard
More Info

DepGuard

Real-time, shift-left dependency vulnerability scanning for package.json, powered by OSV.dev.

Detects vulnerabilities in both direct dependencies and every transitive package installed under them, and attributes the risk back to the top-level entry in package.json that owns it.

Features

  • 🛡️ Inline diagnostics on the exact version string of each vulnerable dependency
  • 🔗 Deep scanning of the entire installed tree via npm ls --all --json
  • 🧭 Transitive vulnerabilities surfaced on the direct dep that pulls them in, with the full dependency path
  • 💡 Quick-fix upgrade action for direct-dep vulnerabilities
  • 🖱️ Rich hover cards with CVE ids, severity, aliases and OSV.dev links
  • ⚡ LRU-cached OSV batch queries and lockfile-keyed dep-tree cache

Requirements

  • Node.js and npm available on PATH (used to gather the installed dep tree)
  • Project must have run npm install at least once so npm ls can resolve versions

Settings

Setting Default Description
depguard.debounceMs 750 Debounce interval before a scan runs after edits
depguard.cacheSize 1000 LRU cache size for package/version lookups
depguard.scanTransitive true Scan the full npm ls tree, not just direct deps
depguard.npmLsTimeoutMs 20000 Timeout for the npm ls invocation
depguard.allowUntrustedConnections false Relax TLS certificate validation behind corporate proxies/firewalls

Upgrading from an older version? Any custom values you'd set under the old fmd.* settings are copied over to depguard.* automatically the first time you activate this version — no action needed.

Commands

  • DepGuard: Show Logs — reveal the extension output channel
  • DepGuard: Rescan Active package.json — force a fresh scan and drop the cached dep tree

License

MIT

  • Contact us
  • Jobs
  • Privacy
  • Manage cookies
  • Terms of use
  • Trademarks
  • Your Privacy Choices
  • Consumer Health Privacy
© 2026 Microsoft