chainsaw pr-scan
Diff manifest/lockfile changes and flag added or upgraded dependencies
Diff manifest/lockfile changes and flag added or upgraded dependencies
chainsaw pr-scan [flags]
Compares manifest and lockfile files between two git refs and reports every newly added or upgraded dependency coordinate (name@version). For each coordinate the offline signal engine emits supply-chain signals; the final verdict is “allow”, “warn”, or “block”.
Intended as a required-status-check companion to chainsaw scan-repo: scan-repo catches committed bypass config; pr-scan catches newly introduced packages.
Verdicts use offline heuristics only — run “chainsaw scan” for full signals.
Exit codes: 0 clean — no warn or block findings 10 one or more warning-level findings 20 one or more blocking findings (also exit 20 with –strict + any warning) 30 one or more monitored manifests failed to parse (dependencies dropped)
Flags
| Flag | Type | Default | Description |
|---|---|---|---|
--base | string | — | Base git ref or SHA to diff from (required) |
--head | string | HEAD | Head git ref or SHA to diff to (default: HEAD) |
--output-file | string | — | Write the report to this path (JSON by default; SARIF with –format=sarif) |
--repo-path | string | . | Path to the git repository |
--strict | bool | — | Escalate warnings to blocking (exit 20 instead of 10) |
The global flags apply here too.