zerodq
v0.2.1
Published
Scan a repository for quantum-vulnerable cryptography, vulnerable dependencies, code, secret, infrastructure and licence risk.
Downloads
35
Maintainers
Readme
zerodq
The command line tool for 0dq.
Scan a repository for quantum-vulnerable cryptography, vulnerable dependencies, code, secret, infrastructure and licence risk.
npx zerodq scan --repo owner/name --fail-on criticalAuthenticating
Create a token at https://0dq.io/settings and put it in ZERODQ_TOKEN.
export ZERODQ_TOKEN=0dq_...(Not 0DQ_TOKEN — a shell variable cannot start with a digit.)
Results are stored against your account, so a scan run in CI appears in the dashboard alongside the ones you run from the browser.
Commands
zerodq scan
| Flag | Meaning |
| --- | --- |
| --repo owner/name | Repository to scan. Inferred from the git remote if omitted. |
| --branch name | Defaults to the repository's default branch. |
| --fail-on <severity> | Exit non-zero when a finding at or above this severity is found. One of critical, high, medium, low. |
| --format <text\|json> | text for a person, json for a pipeline. Defaults to text. |
| --output path | Write the result to a file instead of stdout. |
| --quiet | Suppress progress. |
Exit codes: 0 clean or below the threshold, 1 the gate failed, 2 the scan
could not run. A pipeline should treat 2 differently from 1 — one is a
finding, the other is a broken build step.
zerodq precommit
Scans staged files only, locally, with no network call. It looks for exposed secrets and quantum-vulnerable cryptography, which are the two things worth blocking a commit over, and nothing else. A pre-commit hook that runs a full scan gets uninstalled within a week.
zerodq precommit || exit 1