Scan project lockfiles (npm/pnpm/yarn/pip/go/cargo/maven/gradle) against the free OSV API and report confirmed dependency vulnerabilities with fix versions
dsh plugin --profile web add dsh-dep-vuln-scan
View the source on GitHub