pkgprobe scans your local filesystem for software projects, discovers every dependency — including transitive ones — and surfaces known vulnerabilities in seconds. Native macOS app. No cloud. No signup.
# Third-Party Licenses for my-app
## MIT
- accepts
- axios
- express
- lodash
- semver
## ISC
- glob
- graceful-fs pkgprobe scans what's actually installed on the machine — so security teams can hold the line on policy while developers stay unblocked.
Unlike cloud scanners that only see what's committed, pkgprobe scans what's actually installed — catching version drift, manual installs, and projects that aren't in git.
Node.js (npm, yarn, pnpm), .NET (NuGet), PHP (Composer) — with Python, Java, Rust, Ruby, and Go on the roadmap.
No cloud dependency. Scans run locally in seconds. Vulnerability data is cached with configurable TTL.
Deploy a system-level policy file that users cannot disable. The GUI shows it as read-only with "Managed by your organization".
Every scan, policy evaluation, and config change is logged as structured JSON. Feed it into Splunk, Datadog, or any SIEM.
Ensure every dependency comes from an approved registry. Flag packages that bypassed your private Artifactory or mirror.
Set an interval (1h, 4h, 12h, daily) and pkgprobe re-scans automatically — catching new CVEs as they drop.
Scan a project, surface a CVE, and fix it — without leaving the app. The loop below is a lightweight preview; full screenshots and a recorded demo land with the next release.
Preview visuals. Real screenshots and a recorded walkthrough replace these at launch.
7-day free trial with all features. No credit card required.
For developers
Feature add-ons:
For security teams
Feature packs:
Download pkgprobe, point it at your dev directories, and get a full dependency inventory with vulnerability status in seconds.
Requires macOS 14+. Windows and Linux coming soon.