v2.1.3 · Windows x64
Lockverity symbol

Lockverity

Local-first software assurance

Know what your software contains. Know what the evidence supports.

Lockverity inspects public GitHub repositories and source archives without executing analyzed code. It preserves provenance, keeps missing evidence visible, and gives you a persistent local workspace for software supply-chain review.

Windows 10/11 x64 Per-user installer No admin required Open source
LockverityEvidence-first software supply-chain assurance

Dashboard

At-a-glance evidence of repositories, scans, findings, and provider availability.

APPLICATIONLockverityv2.1.3
DATABASE
available
Connected
REPOSITORIES4Public GitHub + uploads
SCANS12Evidence history
Provider healthView all
githubnot_requested0 records
osvavailable368 records
deps.devavailable1 record
openssfunavailableProvider unavailable
Findings2175
Open findings
Local-firstPersistent desktop workspace
Read-only analysisNo repository code execution
Evidence-honestMissing evidence stays missing
Provenance-preservingClaims trace back to evidence
Why Lockverity

Built for software assurance, not just a CVE list.

Lockverity focuses on what was observed, what supported a finding, and whether provider evidence was complete when the result was produced.

01

Evidence-first assessment

Every conclusion is grounded in an observed manifest, repository file, provider response, or explicit omission state.

OSVavailable
deps.devavailable
OpenSSFunavailable
02

Local workspace

Keep repositories, scans, findings, diagnostics, and evidence history in one desktop application.

03

Hostile-input aware

Uploaded archives are treated as untrusted input. Lockverity does not execute analyzed code or repository scripts.

04

Uncertainty stays visible

Unavailable, partial, degraded, and not-applicable states are kept distinct rather than flattened into a false clean result.

05

Built for review

Revisit results instead of losing context in one-off terminal output. Useful for developers, consultants, and smaller security teams.

How it works

Repository in. Evidence out.

A simple local workflow for checking public repositories or source archives without adopting a full enterprise AppSec platform.

1

Add a repository or archive

Point Lockverity at a public GitHub repository or upload a source ZIP.

2

Collect software evidence

Lockverity identifies manifests, dependencies, provider observations, and relevant supply-chain signals.

3

Review findings with provenance

See what was found, what evidence supported it, and where evidence was incomplete.

4

Keep the assessment

Return later to repositories, scans, findings, and diagnostics in the same local workspace.

Trust & transparency

Verify the binary you run.

The Windows build is currently unsigned, so Windows may show an Unknown Publisher or SmartScreen warning. Lockverity publishes SHA-256 checksums so you can verify the installer before running it.

SHA-256 · Windows installer · v2.1.3831264757dccde2c8feef0422390d9812f053fcad811455bde868756c7757bfd
View release files and checksums on GitHub →

No admin required
Per-user Windows installation.

No analyzed code execution
No npm install, pip install, Makefile, or repository shell execution.

Open source
Inspect the source and star the project on GitHub.

Get Lockverity

Start with a local assessment.

Windows 10/11 x64. The recommended installer is per-user and requires no administrator privileges.

Download startingServed directly from the official GitHub release.