chainsaw pr-scan

Diff manifest/lockfile changes and flag added or upgraded dependencies

Diff manifest/lockfile changes and flag added or upgraded dependencies

chainsaw pr-scan [flags]

Compares manifest and lockfile files between two git refs and reports every newly added or upgraded dependency coordinate (name@version). For each coordinate the offline signal engine emits supply-chain signals; the final verdict is “allow”, “warn”, or “block”.

Intended as a required-status-check companion to chainsaw scan-repo: scan-repo catches committed bypass config; pr-scan catches newly introduced packages.

Verdicts use offline heuristics only — run “chainsaw scan” for full signals.

Exit codes: 0 clean — no warn or block findings 10 one or more warning-level findings 20 one or more blocking findings (also exit 20 with –strict + any warning) 30 one or more monitored manifests failed to parse (dependencies dropped)

Flags

FlagTypeDefaultDescription
--basestring—Base git ref or SHA to diff from (required)
--headstringHEADHead git ref or SHA to diff to (default: HEAD)
--output-filestring—Write the report to this path (JSON by default; SARIF with –format=sarif)
--repo-pathstring.Path to the git repository
--strictbool—Escalate warnings to blocking (exit 20 instead of 10)

The global flags apply here too.