The question I kept asking myself a simple question: Why does checking a dependency for a known vulnerability need to send anything to the cloud? This isn't an argument against cloud-based security tooling . There are good reasons to use centralized services, especially when you need continuously updated data, organization-wide policies, reporting, or large-scale analysis. I was interested in a narrower engineering problem: What would a dependency vulnerability analyzer look like if...