Skip to content
#

dependency-scanner

Here are 71 public repositories matching this topic...

Is your lockfile pwned? 5-second scan of npm/PyPI/Maven/Cargo/Go/RubyGems lockfiles for compromised packages — OSV + curated campaign feed, --min-age cooling-off gate, exit 4 when a scan is incomplete. SLSA L3, Sigstore-signed feed.

  • Updated Oct 4, 2026
  • Python

Educational dependency scanner built in pure Go—parse go.mod and go.sum, inspect direct and indirect modules, query OSV for vulnerabilities, and summarize licenses.

  • Updated Aug 16, 2025
  • Go
postmortem

Supply-chain scanner. Flags malicious install code, typosquats, and shady provenance across your dependencies and your OS packages. Repo-reputation scoring, known-CVE intel, no telemetry.

  • Updated Oct 3, 2026
  • Rust

Deterministic, reachability-aware software composition analysis (SCA) engine — lockfile-first resolution, function- & cross-package reachability, patch-diff symbol mining, EPSS/KEV, SARIF + OpenVEX. Zero runtime dependencies.

  • Updated Jun 11, 2026
  • Python

A local-first application and supply-chain security engine spanning dependency security, install-time enforcement, host inventory, secrets, license compliance, SAST/malware analysis, cloud posture, easm, compliance frameworks mapping, kev, epss, and CI/CD gating.

  • Updated Oct 8, 2026
  • JavaScript

Experimental local CLI for OSV advisory matches plus heuristic supply-chain evidence. Covers 10 ecosystems for OSV, with bounded npm/PyPI file sampling, npm registry metadata, a public-npm install assessment, OSV-cross-checked npm upgrade candidates, JSON/SARIF, and zero external runtime npm dependencies.

  • Updated Aug 29, 2026
  • JavaScript

Add this topic to your repo

To associate your repository with the dependency-scanner topic, visit your repo's landing page and select "manage topics."

Learn more