-
Notifications
You must be signed in to change notification settings - Fork 0
Audit
One command, one graded verdict. audit unifies the signals the other commands
surface separately: the static malware scan, the dependency inventory
and graph health from tree, and (opt-in) online reputation and
known-vulnerability intelligence.
postmortem audit <path> # offline: malware scan + inventory
postmortem audit <path> --online # + source-repo reputation risk
postmortem audit <path> --online --vulns # + known CVE / GHSA / OSV advisoriesaudit ./myproject
ecosystems node, python
packages 313 (14 direct · 299 transitive)
malware 2 finding(s) (1 critical · 1 high · 0 medium · 0 low)
reputation risk 85/100 · 1 high-risk · 3 suspicious
vulns 4 known (worst: high)
verdict CRITICAL malicious code detected
Each row is a self-contained check; the verdict at the bottom is the overall grade, with a one-line reason.
| Grade | When |
|---|---|
| CRITICAL | Malicious code detected (a Critical/High static finding), a High+ known vulnerability, or a high risk score (>= 70). |
| WARN | Softer signals: Medium/Low static findings, graph diagnostics, any known vulnerability, high-risk / suspicious dependencies, or an elevated risk score (>= 40). |
| CLEAN | None of the above. |
| Exit | When |
|---|---|
0 |
Verdict is CLEAN or WARN, and no gate threshold tripped. |
1 |
Verdict is CRITICAL, or a gate threshold tripped. |
2 |
No supported ecosystem found, or the gate is misconfigured (see below). |
The grade is the built-in floor: malicious code fails the build whether or not
you configure anything. On top of it, audit accepts the same
CI gate as tree — the --max-* thresholds, --allow,
--baseline and --config, plus the [gate] table of a postmortem.conf
auto-loaded from the project. Either the grade or the gate failing fails the run.
postmortem audit . --online --vulns --max-high 0 --fail-on-vuln highThresholds are fail-closed: --max-risk / --max-dep / --max-high /
--max-sus need --online, and --max-vulns / --fail-on-vuln need --vulns.
Asking for a threshold over data the run never collected exits 2, because an
unmeasured check is not a passing one.
An exit code says whether the build failed; it cannot say why, and
re-deriving the verdict from scan --json plus tree --json means running both
again. --json emits the same summary the terminal renders:
{
"schema_version": 1,
"verdict": "critical",
"reason": "malicious code detected",
"gate_tripped": null,
"dependencies": { "total": 2, "direct": 1 },
"findings": { "critical": 1, "high": 3, "medium": 3, "low": 1 },
"reputation": null,
"vulnerabilities": null
}null is meaningful throughout: reputation and vulnerabilities are null
when the layer was never run (--online / --vulns absent), which is different
from a zeroed object claiming we looked and found nothing. Likewise
gate_tripped is null with no policy configured, false when a policy ran and
passed.
The exit contract is unchanged by --json.
| Flag | Description |
|---|---|
--online |
Add source-repo reputation risk scoring (network). |
--languages |
With --online, also fetch each repo's language breakdown. |
--vulns |
Add known-vulnerability intelligence (vuln.mlab.sh). |
--allow-test-files |
Report IOC findings inside test/fixture directories too. |
--omit <dev|optional> |
Drop a dependency set. Repeatable. A package reachable from production is always kept — see Dependency scopes. |
--no-progress |
Disable the animated progress UI. |
--json / -o <FILE>
|
Emit the verdict as JSON instead of the terminal view. |
| Gate flags |
--max-risk --max-dep --max-high --max-sus --max-vulns --fail-on-vuln --allow --baseline --config — see CI gate. |
Commands
- scan
- tree
- audit
- fix
- licenses
- why
- diff
- sbom
- system
- scripts
- hook
- watch
- timeline
- ghost
- hunt
- allowlist
- cache
Targets
Ecosystems (overview)
System managers
Windows (overview)
- WinGet
- MSIX / AppX
- Chocolatey
- Scoop
- Add/Remove Programs
- Auto-start (ASEP)
- Scheduled tasks
- Services & drivers
- Jobs & file-based
- Privilege & trust posture
- Network posture
Concepts