SOC toolkit
Am I affected?
Drop a manifest or lockfile here, or click to browse
9 ecosystems, plus CycloneDX SBOM — see the list below
Supported files — 9 ecosystems, plus CycloneDX SBOM
| Language | Ecosystem | Files |
|---|---|---|
| JavaScript / Node | npm | package-lock.json · package.json · yarn.lock · pnpm-lock.yaml |
| Python | PyPI | requirements.txt · poetry.lock · Pipfile.lock |
| Rust | crates.io | Cargo.lock |
| Go | Go | go.mod · go.sum |
| Java / Kotlin | Maven | pom.xml · gradle.lockfile |
| PHP | Packagist | composer.lock |
| Ruby | RubyGems | Gemfile.lock |
| .NET / C# | NuGet | packages.lock.json |
| Dev tools (partial) | mise | mise.lock — only npm: / pipx: / cargo: / gem: / go: / dotnet: backends; runtimes pinned via core:, aqua:, ubi: or asdf: are reported as skipped |
| Any language | CycloneDX SBOM (JSON, via purl) | |
Lockfiles give exact (pinned) versions — the most accurate results. Manifests with version ranges (package.json, pom.xml, unpinned requirements.txt) are resolved best-effort and flagged as approximate.
No manifest scanned yet
Drop a lockfile or SBOM to check your dependencies