chainsaw affected

Find which repos, clients, and SBOMs contain a package or CVE

Find which repos, clients, and SBOMs contain a package or CVE

chainsaw affected <cve|pkg@version> [flags]

Map a CVE / GHSA advisory or a package coordinate to every place it is installed across your org — repository, client, SBOM snapshot, and the transitive dependency path that pulled it in. Backed by the server’s affected-by computation, so no local SBOM is required; results are scoped to your token’s org.

Package coordinates accept an exact version or a range (evaluated per ecosystem), so a whole vulnerable range resolves in one query.

Examples: chainsaw affected CVE-2021-44228 chainsaw affected GHSA-jfh8-c2jp-5v3q chainsaw affected lodash@4.17.20 chainsaw affected “lodash@<4.17.21” –ecosystem npm chainsaw affected CVE-2021-44228 –json

Flags

FlagTypeDefaultDescription
--ecosystemstring—Narrow to one ecosystem (npm, pypi, maven, …); recommended for package lookups
--jsonbool—Output machine-readable JSON

The global flags apply here too.