All tutorials

Every ecosystem

Cordon 0.6.029 sections · 28 diagramsView this tutorial on GitHub

Every package ecosystem Cordon reads, 28 of them, and how to scan each one. The files, the checks and the commands below are rendered from the shipped code, so this page names exactly what a scan reads. The same facts as one table: docs/07-ECOSYSTEMS.md.

   One command reads all of them at once. A repository with a package.json, a   go.mod, a Dockerfile and a workflow is four ecosystems in one scan:   cordon-scanner scan .   Offline by default. --online adds the registry and provenance checks, and   names each package to its own registry; nothing else leaves the machine.

Roles and collections a playbook installs. Ecosystem id ansible.

Every ecosystem, figure 1
┌────────────────────────────────────────────────────────────────────────────┐
│ MANIFESTS       requirements.yml, requirements.yaml,                       │
│                 roles/requirements.yml, collections/requirements.yml,      │
│                 galaxy.yml, meta/main.yml                                  │
│ LOCKFILES       ansible_collections/*/*/MANIFEST.json,                     │
│                 meta/.galaxy_install_info                                  │
│                                                                            │
│ OFFLINE         the dependency graph, lockfile integrity, licences,        │
│                 install hooks                                              │
│                 no advisory feed: said so, as                              │
│                 OPERATIONAL.ADVISORY.NO_FEED.001                           │
│                 typosquats and dependency confusion against its popular    │
│                 names                                                      │
│ WITH --online   registry: withdrawn releases, version distance, hash       │
│                 agreement                                                  │
└────────────────────────────────────────────────────────────────────────────┘
cordon-scanner scan .                      # every file above, in the projectcordon-scanner deps .                      # every package found, with its findings

Modules from the Bazel Central Registry. Ecosystem id bazel.

Every ecosystem, figure 2
┌────────────────────────────────────────────────────────────────────────────┐
│ MANIFESTS       MODULE.bazel, WORKSPACE, WORKSPACE.bazel,                  │
│                 WORKSPACE.bzlmod, BUILD.bazel                              │
│ LOCKFILES       MODULE.bazel.lock                                          │
│                                                                            │
│ OFFLINE         the dependency graph, lockfile integrity, licences,        │
│                 install hooks                                              │
│                 no advisory feed: said so, as                              │
│                 OPERATIONAL.ADVISORY.NO_FEED.001                           │
│                 typosquats and dependency confusion against its popular    │
│                 names                                                      │
│ WITH --online   registry: withdrawn releases, version distance, hash       │
│                 agreement                                                  │
└────────────────────────────────────────────────────────────────────────────┘
cordon-scanner scan .                      # every file above, in the projectcordon-scanner deps .                      # every package found, with its findings

Rust crates from crates.io. Ecosystem id cargo.

Every ecosystem, figure 3
┌────────────────────────────────────────────────────────────────────────────┐
│ MANIFESTS       Cargo.toml, .cargo/config.toml, .cargo/config              │
│ LOCKFILES       Cargo.lock                                                 │
│                                                                            │
│ OFFLINE         the dependency graph, lockfile integrity, licences,        │
│                 install hooks                                              │
│                 known-malicious and known-vulnerable releases, offline     │
│                 typosquats and dependency confusion against its popular    │
│                 names                                                      │
│ WITH --online   registry: withdrawn releases, version distance, hash       │
│                 agreement                                                  │
│                 a published package fetched by digest and compared with    │
│                 the last release                                           │
└────────────────────────────────────────────────────────────────────────────┘
cordon-scanner scan .                      # every file above, in the projectcordon-scanner scan pkg:cargo/<name>@<version> --onlinecordon-scanner deps .                      # every package found, with its findings

IOS and macOS pods. Ecosystem id cocoapods.

Every ecosystem, figure 4
┌────────────────────────────────────────────────────────────────────────────┐
│ MANIFESTS       Podfile, *.podspec                                         │
│ LOCKFILES       Podfile.lock                                               │
│                                                                            │
│ OFFLINE         the dependency graph, lockfile integrity, licences,        │
│                 install hooks                                              │
│                 no advisory feed: said so, as                              │
│                 OPERATIONAL.ADVISORY.NO_FEED.001                           │
│                 typosquats and dependency confusion against its popular    │
│                 names                                                      │
│ WITH --online   registry: withdrawn releases, version distance, hash       │
│                 agreement                                                  │
└────────────────────────────────────────────────────────────────────────────┘
cordon-scanner scan .                      # every file above, in the projectcordon-scanner deps .                      # every package found, with its findings

PHP packages from Packagist. Ecosystem id composer.

Every ecosystem, figure 5
┌────────────────────────────────────────────────────────────────────────────┐
│ MANIFESTS       composer.json, composer.lock, auth.json                    │
│ LOCKFILES       composer.lock                                              │
│                                                                            │
│ OFFLINE         the dependency graph, lockfile integrity, licences,        │
│                 install hooks                                              │
│                 known-malicious and known-vulnerable releases, offline     │
│                 typosquats and dependency confusion against its popular    │
│                 names                                                      │
│ WITH --online   registry: withdrawn releases, version distance, hash       │
│                 agreement                                                  │
└────────────────────────────────────────────────────────────────────────────┘
cordon-scanner scan .                      # every file above, in the projectcordon-scanner deps .                      # every package found, with its findings

C and C++ packages. Ecosystem id conan.

Every ecosystem, figure 6
┌────────────────────────────────────────────────────────────────────────────┐
│ MANIFESTS       conanfile.txt, conanfile.py, profiles/default,             │
│                 conan/profiles/*, remotes.json, conanws.yml, conanws.yaml  │
│ LOCKFILES       conan.lock                                                 │
│                                                                            │
│ OFFLINE         the dependency graph, lockfile integrity, licences,        │
│                 install hooks                                              │
│                 no advisory feed: said so, as                              │
│                 OPERATIONAL.ADVISORY.NO_FEED.001                           │
│                 typosquats and dependency confusion against its popular    │
│                 names                                                      │
│ WITH --online   registry: withdrawn releases, version distance, hash       │
│                 agreement                                                  │
└────────────────────────────────────────────────────────────────────────────┘
cordon-scanner scan .                      # every file above, in the projectcordon-scanner deps .                      # every package found, with its findings

Conda-forge and Anaconda packages. Ecosystem id conda.

Every ecosystem, figure 7
┌────────────────────────────────────────────────────────────────────────────┐
│ MANIFESTS       environment.yml, environment.yaml, meta.yaml               │
│ LOCKFILES       conda-lock.yml, conda-lock.yaml, explicit*.txt,            │
│                 conda-*.lock                                               │
│                                                                            │
│ OFFLINE         the dependency graph, lockfile integrity, licences,        │
│                 install hooks                                              │
│                 no advisory feed: said so, as                              │
│                 OPERATIONAL.ADVISORY.NO_FEED.001                           │
│                 typosquats and dependency confusion against its popular    │
│                 names                                                      │
│ WITH --online   registry: withdrawn releases, version distance, hash       │
│                 agreement                                                  │
└────────────────────────────────────────────────────────────────────────────┘
cordon-scanner scan .                      # every file above, in the projectcordon-scanner deps .                      # every package found, with its findings

The images a Dockerfile, compose file or workload runs. Ecosystem id image.

Every ecosystem, figure 8
┌────────────────────────────────────────────────────────────────────────────┐
│ MANIFESTS       Dockerfile, Dockerfile.*, *.Dockerfile, *.dockerfile,      │
│                 Containerfile, Containerfile.*, compose.yaml, compose.yml, │
│                 compose.*.yaml, compose.*.yml, docker-compose.yml, docker- │
│                 compose.yaml, docker-compose.*.yml, docker-compose.*.yaml, │
│                 k8s/**/*.yaml, k8s/**/*.yml, kubernetes/**/*.yaml,         │
│                 kubernetes/**/*.yml, kube/**/*.yaml, kube/**/*.yml,        │
│                 manifests/**/*.yaml, manifests/**/*.yml, deploy/**/*.yaml, │
│                 deploy/**/*.yml, deployment/**/*.yaml,                     │
│                 deployment/**/*.yml, deployments/**/*.yaml,                │
│                 deployments/**/*.yml, kustomize/**/*.yaml,                 │
│                 kustomize/**/*.yml, overlays/**/*.yaml, overlays/**/*.yml, │
│                 kustomization.yaml, kustomization.yml, deployment.yaml,    │
│                 deployment.yml, statefulset.yaml, statefulset.yml,         │
│                 daemonset.yaml, daemonset.yml, cronjob.yaml, cronjob.yml,  │
│                 job.yaml, job.yml, pod.yaml, pod.yml, *-deployment.yaml,   │
│                 *-deployment.yml, *-statefulset.yaml, *-statefulset.yml,   │
│                 *-daemonset.yaml, *-daemonset.yml, *-cronjob.yaml,         │
│                 *-cronjob.yml, *-job.yaml, *-job.yml, *-pod.yaml,          │
│                 *-pod.yml                                                  │
│ LOCKFILES       none                                                       │
│                                                                            │
│ OFFLINE         the dependency graph, lockfile integrity, licences,        │
│                 install hooks                                              │
│                 no advisory feed: said so, as                              │
│                 OPERATIONAL.ADVISORY.NO_FEED.001                           │
│ WITH --online   registry: withdrawn releases, version distance, hash       │
│                 agreement                                                  │
│                 provenance: whether a build attestation exists, and        │
│                 verifies                                                   │
└────────────────────────────────────────────────────────────────────────────┘
cordon-scanner scan .                      # every file above, in the projectcordon-scanner deps .                      # every package found, with its findings

R packages, through renv. Ecosystem id cran.

Every ecosystem, figure 9
┌────────────────────────────────────────────────────────────────────────────┐
│ MANIFESTS       DESCRIPTION, renv/settings.json, PACKAGES                  │
│ LOCKFILES       renv.lock                                                  │
│                                                                            │
│ OFFLINE         the dependency graph, lockfile integrity, licences,        │
│                 install hooks                                              │
│                 known-malicious and known-vulnerable releases, offline     │
│                 typosquats and dependency confusion against its popular    │
│                 names                                                      │
│ WITH --online   registry: withdrawn releases, version distance, hash       │
│                 agreement                                                  │
└────────────────────────────────────────────────────────────────────────────┘
cordon-scanner scan .                      # every file above, in the projectcordon-scanner deps .                      # every package found, with its findings

Workflows and the actions they use, pinned or not. Ecosystem id actions.

Every ecosystem, figure 10
┌────────────────────────────────────────────────────────────────────────────┐
│ MANIFESTS       .github/workflows/*.yml, .github/workflows/*.yaml,         │
│                 action.yml, action.yaml                                    │
│ LOCKFILES       none                                                       │
│                                                                            │
│ OFFLINE         the dependency graph, lockfile integrity, licences,        │
│                 install hooks                                              │
│                 known-malicious and known-vulnerable releases, offline     │
│                 typosquats and dependency confusion against its popular    │
│                 names                                                      │
│ WITH --online   registry: withdrawn releases, version distance, hash       │
│                 agreement                                                  │
└────────────────────────────────────────────────────────────────────────────┘
cordon-scanner scan .                      # every file above, in the projectcordon-scanner deps .                      # every package found, with its findings

Go modules from the module proxy. Ecosystem id gomod.

Every ecosystem, figure 11
┌────────────────────────────────────────────────────────────────────────────┐
│ MANIFESTS       go.mod, go.work                                            │
│ LOCKFILES       go.mod, go.sum, go.work.sum, vendor/modules.txt            │
│                                                                            │
│ OFFLINE         the dependency graph, lockfile integrity, licences,        │
│                 install hooks                                              │
│                 known-malicious and known-vulnerable releases, offline     │
│                 typosquats and dependency confusion against its popular    │
│                 names                                                      │
│ WITH --online   registry: withdrawn releases, version distance, hash       │
│                 agreement                                                  │
│                 a published package fetched by digest and compared with    │
│                 the last release                                           │
└────────────────────────────────────────────────────────────────────────────┘
cordon-scanner scan .                      # every file above, in the projectcordon-scanner scan pkg:golang/<name>@<version> --onlinecordon-scanner deps .                      # every package found, with its findings

JVM dependencies, Gradle's way. Ecosystem id gradle.

Every ecosystem, figure 12
┌────────────────────────────────────────────────────────────────────────────┐
│ MANIFESTS       build.gradle, build.gradle.kts, settings.gradle,           │
│                 settings.gradle.kts, gradle/libs.versions.toml,            │
│                 gradle/wrapper/gradle-wrapper.properties                   │
│ LOCKFILES       gradle.lockfile, buildscript-gradle.lockfile, settings-    │
│                 gradle.lockfile, gradle/dependency-locks/*.lockfile,       │
│                 gradle/verification-metadata.xml                           │
│                                                                            │
│ OFFLINE         the dependency graph, lockfile integrity, licences,        │
│                 install hooks                                              │
│                 known-malicious and known-vulnerable releases, offline     │
│                 typosquats and dependency confusion against its popular    │
│                 names                                                      │
│ WITH --online   registry: withdrawn releases, version distance, hash       │
│                 agreement                                                  │
│                 provenance: whether a build attestation exists, and        │
│                 verifies                                                   │
└────────────────────────────────────────────────────────────────────────────┘
cordon-scanner scan .                      # every file above, in the projectcordon-scanner deps .                      # every package found, with its findings

Haskell packages, through cabal and stack. Ecosystem id hackage.

Every ecosystem, figure 13
┌────────────────────────────────────────────────────────────────────────────┐
│ MANIFESTS       *.cabal, cabal.project, stack.yaml, package.yaml           │
│ LOCKFILES       cabal.project.freeze, stack.yaml.lock                      │
│                                                                            │
│ OFFLINE         the dependency graph, lockfile integrity, licences,        │
│                 install hooks                                              │
│                 known-malicious and known-vulnerable releases, offline     │
│                 typosquats and dependency confusion against its popular    │
│                 names                                                      │
│ WITH --online   registry: withdrawn releases, version distance, hash       │
│                 agreement                                                  │
└────────────────────────────────────────────────────────────────────────────┘
cordon-scanner scan .                      # every file above, in the projectcordon-scanner deps .                      # every package found, with its findings

Charts a chart depends on. Ecosystem id helm.

Every ecosystem, figure 14
┌────────────────────────────────────────────────────────────────────────────┐
│ MANIFESTS       Chart.yaml, Chart.lock, requirements.lock                  │
│ LOCKFILES       Chart.lock, requirements.lock, charts/*.tgz                │
│                                                                            │
│ OFFLINE         the dependency graph, lockfile integrity, licences,        │
│                 install hooks                                              │
│                 no advisory feed: said so, as                              │
│                 OPERATIONAL.ADVISORY.NO_FEED.001                           │
│                 typosquats and dependency confusion against its popular    │
│                 names                                                      │
│ WITH --online   registry: withdrawn releases, version distance, hash       │
│                 agreement                                                  │
└────────────────────────────────────────────────────────────────────────────┘
cordon-scanner scan .                      # every file above, in the projectcordon-scanner deps .                      # every package found, with its findings

Elixir and Erlang packages. Ecosystem id hex.

Every ecosystem, figure 15
┌────────────────────────────────────────────────────────────────────────────┐
│ MANIFESTS       mix.exs, rebar.config                                      │
│ LOCKFILES       mix.lock, rebar.lock                                       │
│                                                                            │
│ OFFLINE         the dependency graph, lockfile integrity, licences,        │
│                 install hooks                                              │
│                 known-malicious and known-vulnerable releases, offline     │
│                 typosquats and dependency confusion against its popular    │
│                 names                                                      │
│ WITH --online   registry: withdrawn releases, version distance, hash       │
│                 agreement                                                  │
│                 a published package fetched by digest and compared with    │
│                 the last release                                           │
└────────────────────────────────────────────────────────────────────────────┘
cordon-scanner scan .                      # every file above, in the projectcordon-scanner scan pkg:hex/<name>@<version> --onlinecordon-scanner deps .                      # every package found, with its findings

Formulae and casks in a Brewfile. Ecosystem id homebrew.

Every ecosystem, figure 16
┌────────────────────────────────────────────────────────────────────────────┐
│ MANIFESTS       Brewfile, Formula/*.rb, Casks/*.rb, Formula/*/*.rb,        │
│                 Casks/*/*.rb                                               │
│ LOCKFILES       Brewfile.lock.json, Cellar/*/*/INSTALL_RECEIPT.json        │
│                                                                            │
│ OFFLINE         the dependency graph, lockfile integrity, licences,        │
│                 install hooks                                              │
│                 no advisory feed: said so, as                              │
│                 OPERATIONAL.ADVISORY.NO_FEED.001                           │
│                 typosquats and dependency confusion against its popular    │
│                 names                                                      │
│ WITH --online   registry: withdrawn releases, version distance, hash       │
│                 agreement                                                  │
└────────────────────────────────────────────────────────────────────────────┘
cordon-scanner scan .                      # every file above, in the projectcordon-scanner deps .                      # every package found, with its findings

Packages from the General registry. Ecosystem id julia.

Every ecosystem, figure 17
┌────────────────────────────────────────────────────────────────────────────┐
│ MANIFESTS       Project.toml, JuliaProject.toml                            │
│ LOCKFILES       Manifest.toml, JuliaManifest.toml, Manifest-v*.toml,       │
│                 Artifacts.toml                                             │
│                                                                            │
│ OFFLINE         the dependency graph, lockfile integrity, licences,        │
│                 install hooks                                              │
│                 known-malicious and known-vulnerable releases, offline     │
│                 typosquats and dependency confusion against its popular    │
│                 names                                                      │
│ WITH --online   registry: withdrawn releases, version distance, hash       │
│                 agreement                                                  │
└────────────────────────────────────────────────────────────────────────────┘
cordon-scanner scan .                      # every file above, in the projectcordon-scanner deps .                      # every package found, with its findings

JVM dependencies from Maven Central. Ecosystem id maven.

Every ecosystem, figure 18
┌────────────────────────────────────────────────────────────────────────────┐
│ MANIFESTS       pom.xml, .mvn/wrapper/maven-wrapper.properties             │
│ LOCKFILES       dependency-tree.txt, .mvn/checksums/*.sha1,                │
│                 .mvn/checksums/*.sha256, .mvn/checksums/*.sha512           │
│                                                                            │
│ OFFLINE         the dependency graph, lockfile integrity, licences,        │
│                 install hooks                                              │
│                 known-malicious and known-vulnerable releases, offline     │
│                 typosquats and dependency confusion against its popular    │
│                 names                                                      │
│ WITH --online   registry: withdrawn releases, version distance, hash       │
│                 agreement                                                  │
│                 provenance: whether a build attestation exists, and        │
│                 verifies                                                   │
│                 a published package fetched by digest and compared with    │
│                 the last release                                           │
└────────────────────────────────────────────────────────────────────────────┘
cordon-scanner scan .                      # every file above, in the projectcordon-scanner scan pkg:maven/<name>@<version> --onlinecordon-scanner deps .                      # every package found, with its findings

Flake inputs. Ecosystem id nix.

Every ecosystem, figure 19
┌────────────────────────────────────────────────────────────────────────────┐
│ MANIFESTS       flake.nix, default.nix, shell.nix                          │
│ LOCKFILES       flake.lock                                                 │
│                                                                            │
│ OFFLINE         the dependency graph, lockfile integrity, licences,        │
│                 install hooks                                              │
│                 no advisory feed: said so, as                              │
│                 OPERATIONAL.ADVISORY.NO_FEED.001                           │
│                 typosquats and dependency confusion against its popular    │
│                 names                                                      │
└────────────────────────────────────────────────────────────────────────────┘
cordon-scanner scan .                      # every file above, in the projectcordon-scanner deps .                      # every package found, with its findings

JavaScript and TypeScript packages, with npm, pnpm, Yarn or Bun. Ecosystem id npm.

Every ecosystem, figure 20
┌────────────────────────────────────────────────────────────────────────────┐
│ MANIFESTS       package.json, deno.json, deno.jsonc                        │
│ LOCKFILES       package-lock.json, npm-shrinkwrap.json, pnpm-lock.yaml,    │
│                 yarn.lock, bun.lock, deno.lock                             │
│                                                                            │
│ OFFLINE         the dependency graph, lockfile integrity, licences,        │
│                 install hooks                                              │
│                 known-malicious and known-vulnerable releases, offline     │
│                 typosquats and dependency confusion against its popular    │
│                 names                                                      │
│ WITH --online   registry: withdrawn releases, version distance, hash       │
│                 agreement                                                  │
│                 provenance: whether a build attestation exists, and        │
│                 verifies                                                   │
│                 a published package fetched by digest and compared with    │
│                 the last release                                           │
└────────────────────────────────────────────────────────────────────────────┘
cordon-scanner scan .                      # every file above, in the projectcordon-scanner scan pkg:npm/<name>@<version> --onlinecordon-scanner deps .                      # every package found, with its findings

.NET packages. Ecosystem id nuget.

Every ecosystem, figure 21
┌────────────────────────────────────────────────────────────────────────────┐
│ MANIFESTS       *.csproj, *.fsproj, *.vbproj, packages.config,             │
│                 Directory.Packages.props, Directory.Build.props,           │
│                 NuGet.Config, nuget.config, NuGet.config,                  │
│                 obj/project.assets.json                                    │
│ LOCKFILES       packages.lock.json, project.assets.json                    │
│                                                                            │
│ OFFLINE         the dependency graph, lockfile integrity, licences,        │
│                 install hooks                                              │
│                 known-malicious and known-vulnerable releases, offline     │
│                 typosquats and dependency confusion against its popular    │
│                 names                                                      │
│ WITH --online   registry: withdrawn releases, version distance, hash       │
│                 agreement                                                  │
│                 a published package fetched by digest and compared with    │
│                 the last release                                           │
└────────────────────────────────────────────────────────────────────────────┘
cordon-scanner scan .                      # every file above, in the projectcordon-scanner scan pkg:nuget/<name>@<version> --onlinecordon-scanner deps .                      # every package found, with its findings

OCaml packages. Ecosystem id opam.

Every ecosystem, figure 22
┌────────────────────────────────────────────────────────────────────────────┐
│ MANIFESTS       *.opam, opam, dune-project, dune-workspace,                │
│                 dune.lock/lock.dune                                        │
│ LOCKFILES       *.opam.locked, dune.lock/*.pkg                             │
│                                                                            │
│ OFFLINE         the dependency graph, lockfile integrity, licences,        │
│                 install hooks                                              │
│                 known-malicious and known-vulnerable releases, offline     │
│                 typosquats and dependency confusion against its popular    │
│                 names                                                      │
│ WITH --online   registry: withdrawn releases, version distance, hash       │
│                 agreement                                                  │
└────────────────────────────────────────────────────────────────────────────┘
cordon-scanner scan .                      # every file above, in the projectcordon-scanner deps .                      # every package found, with its findings

Dart and Flutter packages. Ecosystem id pub.

Every ecosystem, figure 23
┌────────────────────────────────────────────────────────────────────────────┐
│ MANIFESTS       pubspec.yaml                                               │
│ LOCKFILES       pubspec.lock, .dart_tool/package_config.json               │
│                                                                            │
│ OFFLINE         the dependency graph, lockfile integrity, licences,        │
│                 install hooks                                              │
│                 known-malicious and known-vulnerable releases, offline     │
│                 typosquats and dependency confusion against its popular    │
│                 names                                                      │
│ WITH --online   registry: withdrawn releases, version distance, hash       │
│                 agreement                                                  │
│                 a published package fetched by digest and compared with    │
│                 the last release                                           │
└────────────────────────────────────────────────────────────────────────────┘
cordon-scanner scan .                      # every file above, in the projectcordon-scanner scan pkg:pub/<name>@<version> --onlinecordon-scanner deps .                      # every package found, with its findings

Python packages, with pip, Poetry, Pipenv, PDM or uv. Ecosystem id pypi.

Every ecosystem, figure 24
┌────────────────────────────────────────────────────────────────────────────┐
│ MANIFESTS       pyproject.toml, setup.py, setup.cfg, requirements*.txt,    │
│                 requirements/*.txt, requirements*.in, requirements/*.in,   │
│                 Pipfile                                                    │
│ LOCKFILES       poetry.lock, Pipfile.lock, pdm.lock, uv.lock,              │
│                 requirements*.txt, requirements/*.txt                      │
│                                                                            │
│ OFFLINE         the dependency graph, lockfile integrity, licences,        │
│                 install hooks                                              │
│                 known-malicious and known-vulnerable releases, offline     │
│                 typosquats and dependency confusion against its popular    │
│                 names                                                      │
│ WITH --online   registry: withdrawn releases, version distance, hash       │
│                 agreement                                                  │
│                 provenance: whether a build attestation exists, and        │
│                 verifies                                                   │
│                 a published package fetched by digest and compared with    │
│                 the last release                                           │
└────────────────────────────────────────────────────────────────────────────┘
cordon-scanner scan .                      # every file above, in the projectcordon-scanner scan pkg:pypi/<name>@<version> --onlinecordon-scanner deps .                      # every package found, with its findings

Ruby gems, through Bundler. Ecosystem id rubygems.

Every ecosystem, figure 25
┌────────────────────────────────────────────────────────────────────────────┐
│ MANIFESTS       Gemfile, gems.rb, *.gemspec, .ruby-version                 │
│ LOCKFILES       Gemfile.lock, gems.locked                                  │
│                                                                            │
│ OFFLINE         the dependency graph, lockfile integrity, licences,        │
│                 install hooks                                              │
│                 known-malicious and known-vulnerable releases, offline     │
│                 typosquats and dependency confusion against its popular    │
│                 names                                                      │
│ WITH --online   registry: withdrawn releases, version distance, hash       │
│                 agreement                                                  │
│                 provenance: whether a build attestation exists, and        │
│                 verifies                                                   │
│                 a published package fetched by digest and compared with    │
│                 the last release                                           │
└────────────────────────────────────────────────────────────────────────────┘
cordon-scanner scan .                      # every file above, in the projectcordon-scanner scan pkg:gem/<name>@<version> --onlinecordon-scanner deps .                      # every package found, with its findings

Swift Package Manager dependencies. Ecosystem id swift.

Every ecosystem, figure 26
┌────────────────────────────────────────────────────────────────────────────┐
│ MANIFESTS       Package.swift                                              │
│ LOCKFILES       Package.resolved                                           │
│                                                                            │
│ OFFLINE         the dependency graph, lockfile integrity, licences,        │
│                 install hooks                                              │
│                 known-malicious and known-vulnerable releases, offline     │
│                 typosquats and dependency confusion against its popular    │
│                 names                                                      │
└────────────────────────────────────────────────────────────────────────────┘
cordon-scanner scan .                      # every file above, in the projectcordon-scanner deps .                      # every package found, with its findings

Providers and their pinned hashes. Ecosystem id terraform.

Every ecosystem, figure 27
┌────────────────────────────────────────────────────────────────────────────┐
│ MANIFESTS       *.tf, *.tf.json                                            │
│ LOCKFILES       .terraform.lock.hcl                                        │
│                                                                            │
│ OFFLINE         the dependency graph, lockfile integrity, licences,        │
│                 install hooks                                              │
│                 no advisory feed: said so, as                              │
│                 OPERATIONAL.ADVISORY.NO_FEED.001                           │
│                 typosquats and dependency confusion against its popular    │
│                 names                                                      │
│ WITH --online   registry: withdrawn releases, version distance, hash       │
│                 agreement                                                  │
└────────────────────────────────────────────────────────────────────────────┘
cordon-scanner scan .                      # every file above, in the projectcordon-scanner deps .                      # every package found, with its findings

C and C++ ports. Ecosystem id vcpkg.

Every ecosystem, figure 28
┌────────────────────────────────────────────────────────────────────────────┐
│ MANIFESTS       vcpkg.json, vcpkg-configuration.json, vcpkg-lock.json      │
│ LOCKFILES       vcpkg-lock.json                                            │
│                                                                            │
│ OFFLINE         the dependency graph, lockfile integrity, licences,        │
│                 install hooks                                              │
│                 no advisory feed: said so, as                              │
│                 OPERATIONAL.ADVISORY.NO_FEED.001                           │
│                 typosquats and dependency confusion against its popular    │
│                 names                                                      │
│ WITH --online   registry: withdrawn releases, version distance, hash       │
│                 agreement                                                  │
└────────────────────────────────────────────────────────────────────────────┘
cordon-scanner scan .                      # every file above, in the projectcordon-scanner deps .                      # every package found, with its findings

The source Cordon reads inside any of those projects: 38 languages, each identified by its file name or extension, by a script's interpreter line, or by its content. The last column counts the rule-pack rules written for that language. Every file also gets the checks that are not tied to one language (secrets, hidden characters, obfuscation, known-malware signatures), and Dockerfiles, YAML pipelines, manifests and infrastructure are read by their own detectors (tutorials 07 and 08), so a 0 there is not a file left unread. Every rule is in tutorial 28.

LanguageFilesRule-pack rules
C*.c, *.h0
C#*.cs10
C++*.cc, *.cpp, *.cxx, *.hpp0
Clojure*.bb, *.clj, *.cljc, *.cljs8
CMakeCMakeLists.txt10
Dart*.dart7
DockerfileContainerfile, Dockerfile0
Elixir*.ex, *.exs8
Go*.go10
GroovyJenkinsfile, build.gradle11
Haskell*.hs, *.lhs8
Java*.java10
JavaScript*.cjs, *.js, *.jsx, *.mjs15
JSON*.json0
Julia*.jl8
Kotlin*.kt, *.kts, build.gradle.kts18
Lua*.lua8
MakefileGNUmakefile, Makefile10
Markdown*.markdown, *.md, *.mdc0
Nim*.nim, *.nimble, *.nims7
Objective-C*.m, *.mm8
OCaml*.ml, *.mli8
Perl*.pl, *.pm8
PHP*.php10
PowerShell*.ps1, *.psm110
Python*.pth, *.py, *.pyi, *.pyw, conanfile.py, setup.py17
R*.r8
Ruby*.rb, Gemfile, Podfile, Rakefile10
Rust*.rs, build.rs10
Scala*.scala10
Shell*.bash, *.sh, *.zsh11
SQL*.sql0
Swift*.swift, Package.swift8
TOML*.toml0
TypeScript*.cts, *.mts, *.ts, *.tsx15
XML*.csproj, *.fsproj, *.props, *.targets, *.vbproj, *.xml11
YAML*.yaml, *.yml0
Zig*.zig, build.zig7

Next: 26 · Every command.