Skip to content
#

package-security

Here are 40 public repositories matching this topic...

CLI client (and Golang module) for deps.dev API. Free access to dependencies, licenses, advisories, and other critical health and security signals for open source package versions.

  • Updated Sep 7, 2026
  • Go

Autonomous “Shai-Hulud” engine that ingests malicious NPM package advisories from OSV, tracks versions and metadata, and maintains a continuously updated threat intelligence database.

  • Updated Sep 9, 2026
  • JavaScript

oh supply chain my supply chain — a multi-ecosystem package malware scanner for PyPI, npm, crates.io, and Go. Static analysis plus a sandbox detonation engine, with pluggable detection content (open-core; AGPL engine, Apache-2.0 signatures).

  • Updated Jun 11, 2026
  • Python

Security layer for AI agents: real-time interception of pip/npm/cargo/gem/go installs via Hermes & OpenClaw plugins, Claude Code/Codex hooks, MCP, shell guard, PATH shim, execve, and index proxy. Checks CVEs (OSV/NVD/GitHub), typosquats, malware, licenses, provenance, trust, lockfile hashes. Offline mirror, hash-chained audit, SBOM/SARIF.

  • Updated Jul 6, 2026
  • Python

Add this topic to your repo

To associate your repository with the package-security topic, visit your repo's landing page and select "manage topics."

Learn more