{"actions":{"bootstrapAndRun":{"effect":"installs rote if missing, inspects, prepares, and asks before running","href":"https://play.modiqo.ai/install?play=modiqo/dependency-vulnerability-check@1.1.2","method":"GET","rel":"https://rote.dev/rels/bootstrap-and-run","requiresConsent":true,"responseMediaType":"text/x-shellscript"},"inspect":{"command":"rote play inspect https://play.modiqo.ai/modiqo/dependency-vulnerability-check@1.1.2","effect":"read-only"},"installCliOnly":{"effect":"installs the rote CLI, nothing else","href":"https://play.modiqo.ai/install","method":"GET","rel":"https://rote.dev/rels/install-cli","requiresConsent":true,"responseMediaType":"text/x-shellscript"},"run":{"command":"rote play run https://play.modiqo.ai/modiqo/dependency-vulnerability-check@1.1.2","effect":"executes the play locally after consent","headless":{"approvalAssertion":"--yes","approvalRequiredBeforeInvocation":true,"commandTemplate":"rote play run https://play.modiqo.ai/modiqo/dependency-vulnerability-check@1.1.2 <name=value...> --yes","stdinPolicy":"never pipe input to automate the interactive Ready selector"},"requiresConsent":true}},"description":"Recursively discovers common dependency lockfiles, checks pinned package versions against OSV per ecosystem, and returns deterministic findings with fix versions and novice-friendly guidance. Discovery, the six per-ecosystem OSV queries, detail enrichment, and the report join are separate DAG steps, so ecosystem queries run in parallel, empty ecosystems skip with a label, failed detail lookups degrade to labeled minimal findings, and an interrupted run resumes at the failed stage without re-parsing lockfiles.","distribution":{"digest":"sha256:d9da04cff2af59f6a8eccd48fc2157466ab92b06abd5baf1f83a9956397c9169","mediaType":"application/vnd.modiqo.rote-flow","size":17140,"verifiedBy":"rote verifies the downloaded archive against this digest before it runs"},"effects":{"credentialsProvidedBy":"runner","credentialsRemainLocal":true,"declaredWrites":[],"publisherReceivesCredentials":false},"id":"https://play.modiqo.ai/modiqo/dependency-vulnerability-check@1.1.2","inputPolicy":{"optionalWithDefault":"show_default_and_accept_override","optionalWithoutDefault":"omit_unless_supplied","required":"ask","secrets":"collect_locally_outside_conversation"},"links":{"docs":"https://rote.dev","page":"https://play.modiqo.ai/modiqo/dependency-vulnerability-check@1.1.2","protocol":"https://play.modiqo.ai/.well-known/rote","self":"https://play.modiqo.ai/modiqo/dependency-vulnerability-check@1.1.2.json"},"name":"dependency-vulnerability-check","owner":{"kind":"org","slug":"modiqo"},"parameters":[{"default":".","description":"Project directory or supported lockfile to scan","example":".","input":{"allowCustom":true,"choices":[],"label":"Root"},"name":"root","required":false,"type":"string"},{"default":"auto","description":"Comma-separated ecosystems to include, or auto; accepted values are npm,pypi,cargo,go,packagist,rubygems","example":"npm,pypi","input":{"allowCustom":true,"choices":[],"label":"Ecosystems"},"name":"ecosystems","required":false,"type":"string"},{"default":500,"description":"Maximum unique pinned packages to query, from 1 through 2000","example":500,"input":{"allowCustom":true,"choices":[],"label":"Max packages"},"name":"max_packages","required":false,"type":"integer"},{"default":true,"description":"Include development dependencies when the lockfile identifies them","example":true,"input":{"allowCustom":true,"choices":[],"label":"Include dev"},"name":"include_dev","required":false,"type":"boolean"}],"preparation":[{"action":{"command":"rote play inspect https://play.modiqo.ai/modiqo/dependency-vulnerability-check@1.1.2 --json","effect":"read-only"},"step":1,"type":"inspect_local_readiness"},{"references":["/parameters"],"step":2,"type":"collect_parameters"},{"references":["/parameters","/requirements","/effects"],"step":3,"type":"review"},{"consentBoundary":"the user approves the exact play and parameter values","references":["/parameters","/requirements","/effects"],"step":4,"type":"obtain_run_consent"},{"action":{"command":"rote play run https://play.modiqo.ai/modiqo/dependency-vulnerability-check@1.1.2","headlessCommandTemplate":"rote play run https://play.modiqo.ai/modiqo/dependency-vulnerability-check@1.1.2 <name=value...> --yes"},"preservesAcquisitionBoundaries":["adapter_selection","oauth_dcr","google_discovery","static_token_setup","runtime_security_checks"],"requiresConsent":true,"step":5,"type":"run"}],"producedBy":{"roteVersion":"0.66.1"},"publishedAt":"2026-08-17T23:57:27.313436+00:00","reference":"modiqo/dependency-vulnerability-check@1.1.2","requirements":{"adapters":[],"browser":{"dependencies":[],"runtime":false,"signIn":false},"hostToolRequirements":[{"command":"node","required":true,"versionRequirement":null}],"localTools":["node"],"roteCli":{"minimumVersion":"0.62.0"},"sessions":false},"resolution":"pinned","schema":"rote.play.v1","stats":{"downloads":12,"installs":0},"steps":{"count":10,"names":["compose_report","discover_lockfiles","fetch_details","query_osv_cargo","query_osv_go","query_osv_npm","query_osv_packagist","query_osv_pypi","query_osv_rubygems","validate_input"]},"title":"dependency-vulnerability-check","type":"play","version":"1.1.2","visibility":"public"}