chainsaw scan-repo

Scan a repo tree for Chainsaw-bypass config files

Scan a repo tree for Chainsaw-bypass config files

chainsaw scan-repo [path] [flags]

Walks the given directory (default: current) and flags files that can route package traffic around Chainsaw: committed .npmrc / .yarnrc.yml / .bunfig.toml registries, pip/poetry index-url, Maven <repository>, NuGet packageSources, Cargo [source.*] replace-with entries, GOPROXY overrides, Dockerfile images without the Chainsaw prefix, CocoaPods non-Chainsaw sources, SPM .package(url:) direct dependencies.

Exit codes: 0 the tree is clean 10 at least one bypass file was found 2 the scan could not be completed — the path does not exist, or a file a rule applies to could not be read (a tree that was not fully inspected is not reported as clean)

The exit gate applies to EVERY output format. Choosing –json (or a repo-wide –format json) is a rendering decision and never weakens the verdict.

Gate control: –exit-zero report findings but always exit 0 (monitor mode) –fail-on-unscanned exit 2 when a candidate file could not be inspected. ON by default; pass –fail-on-unscanned=false to downgrade that case to a warning on stderr.

Files larger than 4 MiB are not inspected and are reported as skipped.

Intended for CI preflight (“required status check”).

Flags

FlagTypeDefaultDescription
--exit-zerobool—Always exit 0, even when bypass files are found (report-only mode)
--fail-on-unscannedbooltrueExit 2 when a candidate file could not be inspected (default: on; pass =false to warn only)

The global flags apply here too.