Requirements
skopeoonPATH— image mode- A Go toolchain on
PATH— required at runtime for--repo, which builds and runsgovulncheckitself viago runwithGOTOOLCHAIN=auto gitonPATH— repo mode, unless scanning a local pathgovulncheckonPATH— optional, used only for Go binary mode- Network access for OSV lookups, and for
--repocloning GITHUB_TOKEN/GH_TOKENfor--gistgitand an authenticatedgh— only forcontrib/vexhub-pr.sh, which turns a--vex-outdirectory into a pull request.--vex-outitself needs neither. Addgit-lfsfor--merge-intoagainst a hub that stores its merged report in LFS, as rancher/vexhub does- Python 3.8+ — only for
contrib/vexscan-dashboard.py, which turns a--format jsonreport into an HTML page. Standard library only, and it never touches the network - An LLM provider for
--llm— an endpoint and key, a local model, or an installed CLI. See Choosing a provider; there is no default and nothing is required unless you pass--llm.
All three package databases are parsed in-process — no dpkg, rpm or apk
binary is needed. So are the Python and npm inventories and lock files, and the
Java archives: no python, pip, node, npm, java or unzip is required,
and nothing from the target is ever executed.