Metadata-Version: 2.4
Name: depwarden-cli
Version: 1.0.0
Summary: DepWarden CLI — scan your pip/Poetry/Pipenv project for supply chain vulnerabilities
Author-email: Rushabh Shah <rushabh5000@gmail.com>
License: MIT
Project-URL: Homepage, https://depwarden.in/plugins/python
Project-URL: Repository, https://github.com/Rushabh5000/dep-warden
Project-URL: Issues, https://github.com/Rushabh5000/dep-warden/issues
Keywords: depwarden,sca,security,vulnerability,supply-chain,pip-audit,sbom,dependency-scan,ci,devsecops
Classifier: Programming Language :: Python :: 3
Classifier: License :: OSI Approved :: MIT License
Classifier: Operating System :: OS Independent
Classifier: Topic :: Security
Requires-Python: >=3.8
Description-Content-Type: text/markdown
License-File: LICENSE
Dynamic: license-file

# depwarden-cli

> DepWarden CLI — scan your pip, Poetry, or Pipenv project for supply-chain vulnerabilities.

[![PyPI](https://img.shields.io/pypi/v/depwarden-cli)](https://pypi.org/project/depwarden-cli/)
[![License: MIT](https://img.shields.io/badge/license-MIT-green.svg)](./LICENSE)
[![Website](https://img.shields.io/badge/website-depwarden.in-6366f1)](https://depwarden.in)

## Quick start

```bash
pip install depwarden-cli

APP_API_URL=https://depwarden.in \
APP_API_KEY=DEMO \
depwarden
```

Use `DEMO` as the API key for three free full-fidelity scans.
Get a permanent key at [depwarden.in](https://depwarden.in).

## Installation

```bash
pip install depwarden-cli
```

Zero dependencies beyond the Python standard library — nothing else lands in your
environment.

## Usage

```bash
depwarden [options]
```

The CLI auto-detects your lockfile (`requirements.txt`, `poetry.lock`, `Pipfile.lock`), in
that order.

### Options

| Flag | Default | Description |
|------|---------|-------------|
| `--api-url <url>` | `APP_API_URL` env | DepWarden server base URL |
| `--api-key <key>` | `APP_API_KEY` env | API key (`dw_live_…` or `DEMO`) |
| `--formats <list>` | `html` | Comma-separated report formats: `html,pdf,xlsx,csv` |
| `--report-types <list>` | `risk-summary` | Report types to download |
| `--out <dir>` | `depwarden-reports` | Directory to write downloaded reports |
| `--fail-on-error <bool>` | `true` | Fail the process when gate result is `fail` |
| `--manifest-file <path>` | _(auto-detect)_ | Path to a specific lockfile |
| `--project <name>` | `conformance-fixture` | Project name sent to the API |
| `--timeout <seconds>` | `30` | Per-request timeout |
| `--retries <n>` | `3` | Max retries on transient network errors |
| `--cache-dir <dir>` | `.depwarden-cache` | Offline verdict cache directory |
| `--cache-grace <hours>` | `24` | How long a cached verdict stays valid when offline |
| `--verify-signature` | `false` | Verify the returned verdict's signature server-side |
| `--verbose` / `-v` | `false` | Verbose retry and detection output |

### Environment variables

| Variable | Description |
|----------|-------------|
| `APP_API_URL` | Base URL of your DepWarden instance |
| `APP_API_KEY` | API key — use `DEMO` for free evaluation |

`HTTP_PROXY` / `HTTPS_PROXY` / `NO_PROXY` are honoured automatically (standard
`urllib` behaviour) — no extra configuration needed behind a corporate proxy.

## Exit codes

| Code | Meaning |
|------|---------|
| `0` | Clean scan, or gate failed with `--fail-on-error false` |
| `1` | Gate result is `fail` (build should fail) |
| `2` | Configuration / IO / network error with no cached verdict |
| `3` | Invalid or revoked API key |
| `4` | Quota exceeded or demo allowance exhausted |

## GitHub Actions

```yaml
- name: DepWarden SCA scan
  env:
    APP_API_URL: https://depwarden.in
    APP_API_KEY: ${{ secrets.APP_API_KEY }}
  run: |
    pip install depwarden-cli
    depwarden --formats html --out reports
```

## Download reports

```bash
depwarden --formats html,pdf,xlsx --out ./security-reports
```

## Offline mode

The CLI caches the last successful verdict in `.depwarden-cache/`. If the server is
unreachable, it falls back to the cached result for up to 24 hours (configurable via
`--cache-grace`).

## 💸 Enjoying this? Your wallet has feelings too.

The free tier is real — no account, no credit card, no sighing. But if you've been meaning
to set up proper build gating, PDF reports your manager can pretend to read, and an audit
trail for the one time a log4shell happens on your watch…

**[Upgrade at depwarden.in/pricing →](https://depwarden.in/pricing)**

Plans start at a price that's genuinely less than your last debugging session cost in lost
time. Use `DEMO` as your API key for three full-fidelity test drives before committing.

## Links

- [depwarden.in](https://depwarden.in)
- [Documentation](https://depwarden.in/plugins/python)
- [All plugins](https://depwarden.in/plugins)
- [Pricing](https://depwarden.in/pricing)
- [Support](https://depwarden.in/support)

## License

MIT — see [LICENSE](./LICENSE).
