What It Reads.
Vigilance reads a file, not a language. Point it at a folder, a package, or a build. It reads the source and the binaries inside, and reports what each file can do.
Source
JavaScript, TypeScript, Python, Go, Rust, Java, PHP, shell, PowerShell and more
Packages
npm, PyPI wheels, RubyGems, crates, jars, deb, rpm, MSI, .nupkg, Docker images and more
Archives
tar, zip, 7z, xz, zstd, lz4, CAB, xar, ISO, squashfs and more
Binaries
ELF, PE, Mach-O, .NET, Java, WebAssembly
A format it cannot open yet becomes a loud finding. It never passes as clean, so there is no blind spot to hide in.
How You Point It
You point Vigilance at a file on disk. It reads the installed folder, or the package you downloaded, or a saved container image. It does not pull a package from PyPI or crates.io by name.
The live demo reads npm packages, and it does that download for you. For everything else, point it at the file.