> For the complete documentation index, see [llms.txt](https://docs.stepsecurity.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.stepsecurity.io/packages/oss-package-search.md).

# OSS Package Search

{% hint style="warning" %}
**Available for Enterprise Tier Only**
{% endhint %}

OSS Package Search lets you quickly identify where specific open-source packages appear across your organization, from pull requests and repositories to developer machines. When a package is found to be compromised or vulnerable, you can use this feature to understand your blast radius and take targeted remediation steps.

You can search at the organization level or across your entire tenant, depending on your scope of access.

### **Supported ecosystems**

OSS Package Search supports the following package ecosystems:

* **npm**: the Node.js package registry
* **PyPI**: the Python Package Index
* **Maven**: the Java package ecosystem (Maven Central)
* **NuGet**: the .NET package ecosystem (nuget.org)

Select the ecosystem from the **Package ecosystem** toggle at the top of the search form.

<figure><img src="https://754495266-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FQJRZY4cfEeY3I7DXTOCp%2Fuploads%2FkLZON4hdh1n4RrrR7T8B%2FScreenshot%202026-08-01%20at%2023.13.30.png?alt=media&amp;token=96d8fba1-ccfe-4081-8364-08c3a1de0db9" alt=""><figcaption></figcaption></figure>

### Search Scope

OSS Package Search covers two surfaces:

* **CI/CD and Repositories:** identifies where a package was introduced across pull requests and default branches. Results link directly to the PR where the dependency was added, so you can revert or patch it quickly.
* **Developer Machines:** identifies where a package is installed on developer endpoints, including packages installed by AI coding agents and tools. For each match, the search returns the exact file path and package manager used, which you can use to build an MDM or EDR remediation script and verify removal after cleanup.

### Supported Files

OSS Package Search inspects the following dependency and lock files when indexing packages from CI/CD pipelines, repositories, and developer machines.

#### **npm ecosystem**

| Package manager | Files                             |
| --------------- | --------------------------------- |
| npm             | `package-lock.json`               |
| Yarn            | `yarn.lock`                       |
| pnpm            | `pnpm-lock.yaml`, `pnpm-lock.yml` |
| Bun             | `bun.lock`                        |

#### **PyPI ecosystem**

| Package manager | Files                                                                                                      |
| --------------- | ---------------------------------------------------------------------------------------------------------- |
| pip             | `requirements*.txt`, `requirements*.in`, files inside a `requirements/` directory, `setup.py`, `setup.cfg` |
| Poetry          | `poetry.lock`                                                                                              |
| uv              | `uv.lock`                                                                                                  |
| Pipenv          | `Pipfile.lock`                                                                                             |
| Conda           | `environment.yml`, `environment.yaml`                                                                      |
| PyLock          | `pylock.toml`, `pylock.<name>.toml`                                                                        |

#### **Maven ecosystem**

| Package manager                | Files                                            |
| ------------------------------ | ------------------------------------------------ |
| Maven                          | `pom.xml`, `*.pom`                               |
| Gradle (lock file)             | `gradle.lockfile`, `buildscript-gradle.lockfile` |
| Gradle (verification metadata) | `gradle/verification-metadata.xml`               |
| Bazel (Maven rules)            | `BUILD.bazel`, `MODULE.bazel`, `WORKSPACE`       |

#### **NuGet ecosystem**

| Package manager                    | Files                                               |
| ---------------------------------- | --------------------------------------------------- |
| NuGet (PackageReference)           | `*.csproj`, `*.vbproj`, `*.fsproj`                  |
| NuGet (legacy)                     | `packages.config`                                   |
| NuGet (lock file)                  | `packages.lock.json`                                |
| NuGet (Central Package Management) | `Directory.Packages.props`, `Directory.Build.props` |
| .NET build output                  | `*.deps.json`                                       |

Only `packages.lock.json` records transitive dependencies. The other files list direct dependencies as declared, so a search that relies on them alone will not surface a package that reaches your project indirectly. Enable NuGet lock files if you need transitive coverage.

### How to Use OSS Package Search

**Step 1: Navigate to StepSecurity Dashboard** → OSS Package Search

<figure><img src="https://754495266-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FQJRZY4cfEeY3I7DXTOCp%2Fuploads%2FEh7GoiX1RVaZnWZbh7bf%2FScreenshot%202026-06-16%20at%2014.25.01.png?alt=media&amp;token=499cb708-3d24-42ab-944c-657edd997497" alt=""><figcaption></figcaption></figure>

**Step 2: Configure your search filters**

* **Search Scope**: choose **Organization Search** to search within your current organization, or **Tenant Search** to search across all organizations in your tenant.
* **Package ecosystem**: choose **npm**, **PyPI**, **Maven**, or **NuGet**.
* **Search Type**: choose **Custom Search** to specify packages manually, or a compromised packages search such as **Compromised Packages (Exact Versions)** to check your organization against known compromised packages.
* **Repository**: optionally narrow results to a specific repository.
* **Seen In**: filter by where the package was detected. Options include *All (PRs, Default Branch & Dev Machines)*, or a specific surface.
* **Time Range**: optionally select a date range to limit results.

When you choose a compromised packages search, **Packages included in this search** shows how many packages and versions the search covers. Select **View all** to see the full list.

<figure><img src="https://754495266-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FQJRZY4cfEeY3I7DXTOCp%2Fuploads%2FkLZON4hdh1n4RrrR7T8B%2FScreenshot%202026-08-01%20at%2023.13.30.png?alt=media&amp;token=96d8fba1-ccfe-4081-8364-08c3a1de0db9" alt=""><figcaption></figcaption></figure>

**Step 3: Add the packages you want to search for.**

Enter a package name and, if applicable, one or more specific versions. Click **Add Package** to add more packages to the same search. Results can be exported as CSV.

<figure><img src="https://754495266-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FQJRZY4cfEeY3I7DXTOCp%2Fuploads%2FA8RMG28sN3wsX0waMewu%2FScreenshot%202026-05-13%20at%2021.01.33.png?alt=media&amp;token=45535ec3-462a-4aa5-aaeb-010c520dfc55" alt=""><figcaption></figcaption></figure>

**Step 4: Run the search**

Click **Search**. A search can take one to two minutes to finish.

While the search runs:

* The **Search** button changes to **Stop**. Hover over **Stop** to see how far the search has progressed, or click it to end the search early.
* Results appear as they are found, so you can start reviewing them before the search finishes.
* Each results section shows *Searching for matching results* until it has results to display. You can collapse a section while the search continues.

<figure><img src="https://754495266-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FQJRZY4cfEeY3I7DXTOCp%2Fuploads%2FyY0AsAba22KyrF8sU9HF%2FScreenshot%202026-09-30%20at%2014.46.52.png?alt=media&amp;token=305e465b-0b7e-49a2-bc70-ce8a8b0da3db" alt=""><figcaption></figcaption></figure>

**Step 5: Review the results**

The results header shows how many results were found. Results are grouped into two collapsible sections, each with its own search box for narrowing the loaded results:

* **PRs and Default Branch**: each finding shows the pull request title and number, the repository, the author, the file the package was detected in (for example `package-lock.json`), and when it was last updated. The matching package version appears below the finding. Click **View PR** to open the pull request.

<figure><img src="https://754495266-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FQJRZY4cfEeY3I7DXTOCp%2Fuploads%2FWq206rMbM2EZFWYfO3lU%2FScreenshot%202026-09-30%20at%2014.47.54.png?alt=media&amp;token=af91f02a-3998-40ef-ab0d-929beb3c609f" alt=""><figcaption></figcaption></figure>

* **Dev Machines**: each device shows its hostname, user, and platform, followed by a table of matching packages with **First Seen**, **Last Seen**, **Project Path**, and **Status**. Select **View all** below the table to see every matching package on that device.

<figure><img src="https://754495266-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FQJRZY4cfEeY3I7DXTOCp%2Fuploads%2FLOIbtp0hd5G95rd4Wt4h%2FScreenshot%202026-09-30%20at%2014.48.19.png?alt=media&amp;token=6578fed7-b838-4972-bbcc-70f080b45257" alt=""><figcaption></figcaption></figure>

Use the **Package Status** filter in the results header to narrow the results by status, and **Export received results** to download the results received so far.

**Follow this interactive demo to see how this works:**

{% embed url="<https://app.storylane.io/share/ikokjxskmmum>" %}

{% hint style="info" %}
For a complete guide to preventing, detecting, and responding to package attacks, see [OSS Supply Chain Security](https://docs.stepsecurity.io/oss-supply-chain-security/)
{% endhint %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.stepsecurity.io/packages/oss-package-search.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
