For the complete documentation index, see llms.txt. This page is also available as Markdown.

CLI workflow

Shift-left context

The Cortex CLI runs malicious package detection during CI scans, so a CI pipeline can surface malicious dependencies before an artifact is built or deployed. Malicious package detection is gated by the same feature flag as the other channels.

Review malicious package detection in the CLI

During a CI scan, the CLI prints a per-file Malicious Packages summary table alongside the existing CVE table. The table includes the columns Package (<name>@<version>), Malware ID (for example, MAL-2026-4270), Severity (always CRITICAL), Summary (the OSV advisory summary, truncated), and Advisory (the OSV URL). Fix-version columns are omitted because OSV malicious-package entries carry no fix-version metadata — the remediation is to remove the package. Withdrawn advisories are dropped and do not appear in the table.

NOTE: When the malicious packages check cannot complete during a CLI or CI scan (service unreachable or data stale), the scan continues and produces all other findings, emits a CRITICAL-level error log, and reports the malicious packages sub-check as failed. The scan is never blocked by a malicious package check failure.

Last updated

Was this helpful?