DepTrack
May 11, 2025 · View on GitHub
Dependency & Security Tracker for VS Code
DepTrack is a lightweight Visual Studio Code extension that helps you keep your project dependencies and code quality in check. With a single dashboard you can scan for outdated packages, security vulnerabilities, license issues, code smells and more—right inside your editor.
Version: 0.0.1
Publisher: AmanKumar
Display Name: DepTrack
Description: Dependency & Security Tracker for Visual Studio Code
Table of Contents
- Supported Operating Systems
- Prerequisites
- Installation
- Usage
- Key Features
- Configuration
- Development & Building from Source
- Troubleshooting
- License
Supported Operating Systems
- Windows: Windows 10 or later
- macOS: macOS 11 (Big Sur) or later
- Linux: Ubuntu 18.04+, Fedora 33+, Debian 10+, Arch Linux (Any distro supported by VS Code)
DepTrack is a pure JavaScript/HTML extension and runs on any OS supported by Visual Studio Code.
Prerequisites
-
Visual Studio Code version 1.88.0 or later
-
.VSIX package for DepTrack (e.g.
deptrack-0.0.4.vsix) -
Node.js v16.0.0 or later and npm v8.0.0 or later (only required if building from source)
-
The following CLI tools installed globally (required for full functionality):
npm install -g snyk eslint jscpd jsinspect plato chokidar-cli jest license-checker sonar-scanner
export SNYK_TOKEN="a6f20f51-3dc5-4112-a309-2623229b3e2f"
snyk config set org=amankmr417310
Installation
1. Install from VSIX (Recommended)
- Download
deptrack.vsixto your local machine. - Open Visual Studio Code.
- Go to Extensions sidebar (⇧⌘X / Ctrl+Shift+X).
- Click the ⋯ menu in the top-right corner of the Extensions view.
- Choose Install from VSIX…
- Browse to and select your downloaded
deptrack.vsix. - After installation, click Reload when prompted.
2. Install via Command-Line
code --install-extension path/to/deptrack-0.0.4.vsix
Replace the path with wherever you saved the file. After installation, restart VS Code or run Developer: Reload Window.
Usage
- Open the Command Palette (⇧⌘P / Ctrl+Shift+P).
- Type DepTrack: to see available commands.
- Run DepTrack: DepTrack: Open Dashboard to bring up the DepTrack panel.
- Use the toolbar buttons to scan for:
- Outdated Packages
- Vulnerabilities
- License Issues
- ESLint Issues
- Code Duplication
- Cyclomatic Complexity
- Secrets
- Dependency Graph
- Sonar Report
- Suggested fixes
- Industry Standard Code
- Chatbot Assistance
Key Features
-
Outdated Packages
Quickly identify and update npm packages that are behind the latest published versions. -
Vulnerability Scanning
Integrates with Snyk and other vulnerability databases to highlight known security issues. -
License Compliance
Detects forbidden or incompatible licenses in your dependency tree. -
ESLint Issues
Runs ESLint rules and shows errors and warnings directly in the dashboard. -
Code Duplication
Uses JSCPD to find and report duplicated code blocks across your project. -
Cyclomatic Complexity & SLOC
Computes complexity metrics and maintainability scores to pinpoint potentially problematic code. -
Secrets Detection
Scans for accidentally committed API keys, passwords, and other secrets. -
Standards Conformance
Check your code if it follows industry standards. -
Dependency Graph
Visualizes your project’s dependency graph with major version breakdowns. -
Sonar Integration
Pulls in SonarQube metrics (bugs, code smells, coverage, duplication) for a holistic quality overview. -
Export & Reports
• Export scan results as CSV or PDF
• Send email alerts or schedule PDF/CSV reports via SMTP -
AI-Powered Chatbot
Ask questions, get suggestions or guidance about your code and dependencies using built-in AI assistance.
Configuration
You can configure DepTrack settings in your VS Code Settings (settings.json):
{
"deptrack.email.service": "gmail",
"deptrack.email.auth.user": "<your-email@example.com>",
"deptrack.email.auth.pass": "<your-email-password-or-app-token>",
"deptrack.email.to": "<recipient@example.com>",
"deptrack.snykOrg": "<your-snyk-organization-id>",
"deptrack.snykOrg": "amankmr417310"
}
(Optional) Use Preconfigured Snyk Token
To use the built-in Snyk scanning feature without setting up your own Snyk account, you can optionally export a predefined token:
export SNYK_TOKEN="a6f20f51-3dc5-4112-a309-2623229b3e2f"
⚠️ Warning: This token belongs to the extension publisher and usage is monitored. Abuse or misuse will result in revocation.
If you prefer to use your own Snyk account, simply run:
snyk auth
Development & Building from Source
If you wish to modify or rebuild DepTrack:
1.Clone the repository
git clone https://github.com/deptrack/deptrack-vscode.git
cd deptrack-vscode
2.Install dev dependencies
npm install
3. Install Global CLI Tools:
Run below command to put all required CLIs on your PATH:
npm install -g vsce snyk eslint jscpd jsinspect plato chokidar-cli jest license-checker sonar-scanner
export SNYK_TOKEN="a6f20f51-3dc5-4112-a309-2623229b3e2f"
snyk config set org=amankmr417310
4.Build/Bundle
DepTrack is distributed as CommonJS; no transpilation is required.
npm run build
5.Run Extension in VS Code
- Open this folder in VS Code.
- Press F5 to launch the extension in a new Extension Development Host window.
Troubleshooting
1.Extension failed to activate
Verify your VS Code version is ≥ 1.88.0. Reload the window (⇧⌘P / Ctrl+Shift+P → Developer: Reload Window).
2.Email not sending
Double-check SMTP settings under deptrack.email.*. If using Gmail, you may need an App Password.
3.Snyk integration errors
Ensure deptrack.snykOrg is correctly set in settings.
Tip:
You can also run:
code --uninstall-extension deptrack.deptrack
to remove the extension.
If you’re developing locally, open your extension folder in VS Code and press F5 to launch a Development Host with your latest changes.
License
Copyright (c) 2025 Aman Kumar
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the “Software”), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in
all copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED “AS IS”, WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.