chainsaw scan-remote

Upload a single lockfile to the server and stream the aggregated intelligence report

Upload a single lockfile to the server and stream the aggregated intelligence report

chainsaw scan-remote <lockfile> [flags]

Upload a lockfile (any ecosystem the server supports — npm, pypi, cargo, maven, go, rubygems, composer, nuget, …) and poll the server’s scan job until the aggregate intelligence report is ready.

Exit codes: 0 — no critical or high findings (or –exit-zero was passed) 1 — at least one critical or high finding

The exit gate applies to EVERY output format. Choosing –json (or a repo-wide –format json) is a rendering decision and never weakens the verdict.

Examples: chainsaw scan-remote ./package-lock.json chainsaw scan-remote ./Cargo.lock –json chainsaw scan-remote ./poetry.lock –timeout 5m chainsaw scan-remote ./package-lock.json –json –exit-zero # collect, don’t gate

Flags

FlagTypeDefaultDescription
--exit-zerobool—Always exit 0, even when critical/high findings are reported (report-only mode)
--timeoutduration5m0sMaximum time to wait for the server to finish processing pending packages

The global flags apply here too.