chainsaw scan-repo
Scan a repo tree for Chainsaw-bypass config files
Scan a repo tree for Chainsaw-bypass config files
chainsaw scan-repo [path] [flags]
Walks the given directory (default: current) and flags files that can route package traffic around Chainsaw: committed .npmrc / .yarnrc.yml / .bunfig.toml registries, pip/poetry index-url, Maven <repository>, NuGet packageSources, Cargo [source.*] replace-with entries, GOPROXY overrides, Dockerfile images without the Chainsaw prefix, CocoaPods non-Chainsaw sources, SPM .package(url:) direct dependencies.
Exit codes: 0 the tree is clean 10 at least one bypass file was found 2 the scan could not be completed — the path does not exist, or a file a rule applies to could not be read (a tree that was not fully inspected is not reported as clean)
The exit gate applies to EVERY output format. Choosing –json (or a repo-wide –format json) is a rendering decision and never weakens the verdict.
Gate control: –exit-zero report findings but always exit 0 (monitor mode) –fail-on-unscanned exit 2 when a candidate file could not be inspected. ON by default; pass –fail-on-unscanned=false to downgrade that case to a warning on stderr.
Files larger than 4 MiB are not inspected and are reported as skipped.
Intended for CI preflight (“required status check”).
Flags
| Flag | Type | Default | Description |
|---|---|---|---|
--exit-zero | bool | — | Always exit 0, even when bypass files are found (report-only mode) |
--fail-on-unscanned | bool | true | Exit 2 when a candidate file could not be inspected (default: on; pass =false to warn only) |
The global flags apply here too.