CLI workflow
Shift-left context
The Cortex CLI runs malicious package detection during CI scans, so a CI pipeline can surface malicious dependencies before an artifact is built or deployed. Malicious package detection is gated by the same feature flag as the other channels.
Review malicious package detection in the CLI
During a CI scan, the CLI prints a per-file Malicious Packages summary table alongside the existing CVE table. The table includes the columns Package (<name>@<version>), Malware ID (for example, MAL-2026-4270), Severity (always CRITICAL), Summary (the OSV advisory summary, truncated), and Advisory (the OSV URL). Fix-version columns are omitted because OSV malicious-package entries carry no fix-version metadata — the remediation is to remove the package. Withdrawn advisories are dropped and do not appear in the table.
NOTE: When the malicious packages check cannot complete during a CLI or CI scan (service unreachable or data stale), the scan continues and produces all other findings, emits a CRITICAL-level error log, and reports the malicious packages sub-check as failed. The scan is never blocked by a malicious package check failure.
Last updated
Was this helpful?
