sealift

module
v0.2.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 23, 2026 License: GPL-3.0

README

sealift

ci latest release

sealift prepares npm dependency updates for air-gapped networks. It scans a project for known vulnerabilities, ranks the newer versions of each dependency, and packs the chosen versions into an archive an offline registry can import.

Install

docker run -d \
  --name sealift \
  -p 127.0.0.1:8080:8080 \
  -v sealift-data:/data \
  ghcr.io/morgankryze/sealift:latest

-p 127.0.0.1:8080:8080 keeps the interface off the network; reach it through a tunnel or a reverse proxy instead of publishing it further. The named volume sealift-data holds every project, analysis, export and setting, so it survives a container restart or upgrade.

Open http://localhost:8080.

Usage

On first run, sealift asks for Trivy, its vulnerability database and the signature key your Nexus import checks. It downloads nothing until you press Install, then shows each tool downloading and ready before you continue. When the latest Trivy release is younger than the minimum release age, it offers the newest release past that age instead.

The setup screen, listing Trivy, its vulnerability database and the signature key, with an install button naming both download sizes

Drop a project's package.json. Its direct dependencies must be pinned to exact versions; the preview lists anything sealift would refuse before you start. If you dropped the same file before, sealift offers to resume that session.

sealift resolves the project, scans it with Trivy, lists the newer versions of each dependency, and resolves each candidate against the rest of the project. The screen shows each step as it finishes, with the time left. You can close the page; the session keeps running.

The analysis screen, with five finished steps, candidate resolution at 14 of 254, and about 1 minute 20 seconds left

Review sealift's proposal. For each dependency it picks the oldest version that fixes the most CVEs, and holds back any release younger than the minimum release age. A proposal that is a major jump, or a 0.x minor jump, waits under "To decide". Open a row to see the CVE ids behind the current version, then choose another candidate or keep the current one.

Confirm the selection. sealift resolves the project against it, downloads each package, checks its integrity, and packs packages_npm.tar.gz with the signature key, next to a CVE report, a CycloneDX SBOM and a summary. Carry the archive through your kiosk and import it on the air-gapped side.

Configuration

Every setting lives in the Settings panel, opened from the header, and applies to the next analysis or export. The panel also holds the light, dark or system theme.

Setting Changes
Target The OS, CPU, libc, Node version and pnpm version sealift resolves and downloads packages for.
Signature key Written into signature.key inside every export archive. Masked once set; sealift never logs it.
Minimum release age How many days old a release must be before sealift proposes it or installs it as Trivy. 14 by default.
Resolve parallelism How many candidate versions sealift resolves at once.
Download parallelism How many package tarballs sealift downloads at once.

Development

Requires Go 1.27, Node 22, pnpm 12.3.4, just and golangci-lint 2.13.

just hooks      # link the pre-commit hook
just check      # formatting, vet, lint, race tests
just web-check  # typecheck, lint and test the web app
just generate   # regenerate the Go server and the web client from api/openapi.yaml
just image      # build the image for the host's own architecture
just e2e        # publish to a local registry, then pnpm install against it

License

GPL-3.0. See LICENSE.

Directories

Path Synopsis
Package archive writes reproducible tar.gz archives: for a given build of sealift, the same entries always give the same bytes.
Package archive writes reproducible tar.gz archives: for a given build of sealift, the same entries always give the same bytes.
cmd
sealift command
Command sealift serves the sealift backend.
Command sealift serves the sealift backend.
internal
api
Package api provides primitives to interact with the openapi HTTP API.
Package api provides primitives to interact with the openapi HTTP API.
jobs
Package jobs runs analysis and export jobs one at a time and streams their events to the interface.
Package jobs runs analysis and export jobs one at a time and streams their events to the interface.
report
Package report builds the files an export writes beside its archive: manifest.json, findings.csv and summary.md.
Package report builds the files an export writes beside its archive: manifest.json, findings.csv and summary.md.
runner
Package runner starts pnpm and Trivy as subprocesses: it writes their input files, runs the binary, and gives the caller the combined output.
Package runner starts pnpm and Trivy as subprocesses: it writes their input files, runs the binary, and gives the caller the combined output.
store
Package store keeps sealift's data volume: settings, projects, analyses and exports.
Package store keeps sealift's data volume: settings, projects, analyses and exports.
tools
Package tools installs and manages the pnpm and Trivy binaries that sealift's jobs run as subprocesses.
Package tools installs and manages the pnpm and Trivy binaries that sealift's jobs run as subprocesses.
Package npm reads npm and pnpm data: package.json manifests, pnpm lockfiles, registry metadata and package tarballs.
Package npm reads npm and pnpm data: package.json manifests, pnpm lockfiles, registry metadata and package tarballs.
Package rank scores vulnerability findings, flags risky candidate versions, and picks the best candidate version of a dependency.
Package rank scores vulnerability findings, flags risky candidate versions, and picks the best candidate version of a dependency.
Package sbom writes CycloneDX software bills of materials for npm packages.
Package sbom writes CycloneDX software bills of materials for npm packages.
Package web embeds the built frontend so cmd/sealift can serve it alongside the API, with no separate static asset directory to deploy.
Package web embeds the built frontend so cmd/sealift can serve it alongside the API, with no separate static asset directory to deploy.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL