chainsaw affected
Find which repos, clients, and SBOMs contain a package or CVE
Find which repos, clients, and SBOMs contain a package or CVE
chainsaw affected <cve|pkg@version> [flags]
Map a CVE / GHSA advisory or a package coordinate to every place it is installed across your org — repository, client, SBOM snapshot, and the transitive dependency path that pulled it in. Backed by the server’s affected-by computation, so no local SBOM is required; results are scoped to your token’s org.
Package coordinates accept an exact version or a range (evaluated per ecosystem), so a whole vulnerable range resolves in one query.
Examples: chainsaw affected CVE-2021-44228 chainsaw affected GHSA-jfh8-c2jp-5v3q chainsaw affected lodash@4.17.20 chainsaw affected “lodash@<4.17.21” –ecosystem npm chainsaw affected CVE-2021-44228 –json
Flags
| Flag | Type | Default | Description |
|---|---|---|---|
--ecosystem | string | — | Narrow to one ecosystem (npm, pypi, maven, …); recommended for package lookups |
--json | bool | — | Output machine-readable JSON |
The global flags apply here too.