Package manifest coverage
This page lists the package manifest formats supported by Spectra Assure, Spectra Code, Spectra Resolve and rl-protect - complementary tools for identifying risks in open source software (OSS) dependencies and software packages.
rl-protect is a command-line solution designed for a shift-left approach to vulnerability and threat detection.
It scans package manifest files and checks declared dependencies for security risks by connecting to the Spectra Assure Community database of analyzed software packages from popular communities, quickly identifying known issues without requiring full package analysis.
Spectra Resolve is a desktop application based on rl-protect and supports the same package manifest formats.
Spectra Code is a VS Code extension that helps users identify and assess vulnerable dependencies early in development, both in their projects and in enabled VS Code extensions - all directly within VS Code.
It uses rl-protect internally, surfacing the same manifest-scanning results directly in the editor instead of the command line.
On the other hand, Spectra Assure focuses on software assurance and supply chain security by analyzing both OSS components and complete software packages as they are distributed. It operates without requiring source code and is most effective when used continuously to track changes in risk across releases and detect emerging threats.
As Spectra Assure analyzes release artifacts, it does not support lock files, since they are typically not included in published packages.
Use the reference tables below to select a community and check which package manifests are supported across ReversingLabs products:
The version listed in the table indicates the minimum versions of rl-protect and Spectra Code required to analyze the corresponding manifest files.
Since these two tools do not update automatically, be sure to download new versions of rl-protect and Spectra Code as they are released to ensure support for all required manifest files.
Node.js / VS Codeโ
| Manifest File | Spectra Assure | Spectra Code (v1.0.0) | rl-protect (v1.1.0) |
|---|---|---|---|
| package.json | โ | โ | โ |
| package-lock.json | โ | โ | โ |
| pnpm-lock.yaml | โ | โ | โ |
| yarn.lock (Classic) | โ | โ | โ |
| yarn.lock (Modern) | โ | โ | โ |
Pythonโ
| Manifest File | Spectra Assure | Spectra Code (v1.0.0) | rl-protect (v1.1.0) |
|---|---|---|---|
| requirements.txt | โ | โ | โ |
| pyproject.toml | โ | โ | โ |
| setup.cfg | โ | โ | โ |
| Pipfile | โ | โ | โ |
| Pipfile.lock | โ | โ | โ |
| poetry.lock | โ | โ | โ |
| pdm.lock | โ | โ | โ |
| uv.lock | โ | โ | โ |
Rubyโ
| Manifest File | Spectra Assure | Spectra Code (v1.0.0) | rl-protect (v1.1.0) |
|---|---|---|---|
| gemfile | โ | โ | โ |
| gemspec | โ | โ | โ |
| gemfile.lock | โ | โ | โ |