How to use “Dependency Vulnerability Scanner”

Dependency Vulnerability Scanner belongs to the web operation tools on KivTools. The workbench above handles the whole job on one screen: files chosen from your device, then a text result you can copy.

The conversion runs inside the page with browser JavaScript. Nothing you enter is uploaded, the tool keeps working offline, and it is safe for data you are not allowed to send to a third party.

  1. Paste or type your input into the field above.
  2. Select the file to process with the file picker above.
  3. Press Scan dependencies to generate the result.
  4. Press Clear to reset the form before the next run.
  5. Check the result against a second source before you rely on it in production.

Background and accuracy

Web operation tools

Web infrastructure problems are usually visible only from the outside: what DNS answers, which headers a server returns, whether a redirect loops or a certificate covers the hostname. These tools inspect a live endpoint from the public internet and report what an ordinary client would see.

A single probe is a snapshot, not a guarantee. GeoDNS, CDNs and caches can answer differently from another network, so compare results from a second vantage point before changing production settings.

Getting reliable results

Browsers, desktop tools and command-line utilities should agree on the result; a mismatch usually means a different encoding, locale or version. Reproduce the finding with the platform’s own tools (dig, curl -I, openssl s_client) before you act on it; the numbers should agree.

Timeouts and blocked ports often come from firewalls or ISPs on the path, not from the target service itself, which is why an external check is a useful second opinion. Keep a copy of the input while you experiment, so a wrong setting never destroys the source.

Practical details

Input & output

Takes package manifests, lockfiles, requirements.txt, Maven XML, or CycloneDX files (.json, .lock, .txt, .xml) and returns OSV vulnerability findings for up to 100 exact versioned dependencies.

Common uses

Check a Python requirements.txt before release; audit a CycloneDX SBOM during CI; verify a suspicious npm lockfile entry after a supply-chain alert.

Processing & privacy

The manifest is parsed in the browser, then exact package ecosystem, name, and version values are sent to OSV.dev for vulnerability lookup.

Limits & compatibility

Supports only exact version pins, not ranges or wildcards; limited to 100 packages per scan.

Frequently asked questions

Is Dependency Vulnerability Scanner free to use?

Yes. Every tool on KivTools is free, needs no account and has no usage quota. There is no paid tier hiding behind the workbench, and no email address is required to use the result.

Where is my data processed?

Inside your browser. The page loads a script once and the conversion happens on your machine, which is also why the tool still works when the network drops.

What can I feed into Dependency Vulnerability Scanner?

Takes package manifests, lockfiles, requirements.txt, Maven XML, or CycloneDX files (.json, .lock, .txt, .xml) and returns OSV vulnerability findings for up to 100 exact versioned dependencies. Large inputs are usually handled without trouble, but extremely large ones are better processed in a local command-line tool.

How accurate is the result?

Configuration is only real once it is served: verify the header or rule on the live response. Compare a small known-good sample first when the output feeds an automated pipeline.

Can I use the output commercially?

The output is yours: no watermark, no licence tag, no attribution requirement. Check the underlying format or library licence when the result ships in a product.

Does it work on mobile and offline?

The page works in any modern mobile browser, and the layout collapses to a single column on small screens. Local tools keep working offline once the page has loaded.

Recent tools: