pkgprobe scans your local filesystem for software projects, discovers every dependency — including transitive ones — and surfaces known vulnerabilities in seconds. Native macOS app. No cloud. No signup.
# Third-Party Licenses for my-app
## MIT
- accepts
- axios
- express
- lodash
- semver
## ISC
- glob
- graceful-fs Unlike cloud scanners that only see what's committed, pkgprobe scans what's actually installed — catching version drift, manual installs, and projects that aren't in git.
Node.js (npm, yarn, pnpm), .NET (NuGet), PHP (Composer) — with Python, Java, Rust, Ruby, and Go on the roadmap.
No cloud dependency. Scans run locally in seconds. Vulnerability data is cached with configurable TTL.
Deploy a system-level policy file that users cannot disable. The GUI shows it as read-only with "Managed by your organization".
Every scan, policy evaluation, and config change is logged as structured JSON. Feed it into Splunk, Datadog, or any SIEM.
Ensure every dependency comes from an approved registry. Flag packages that bypassed your private Artifactory or mirror.
Set an interval (1h, 4h, 12h, daily) and pkgprobe re-scans automatically — catching new CVEs as they drop.
7-day free trial with all features. No credit card required.
For developers
Feature add-ons:
For security teams
Feature packs:
Download pkgprobe, point it at your dev directories, and get a full dependency inventory with vulnerability status in seconds.
Requires macOS 14+. Windows and Linux coming soon.