Audits AUR PKGBUILD updates before you install: detects structural changes, suspicious commands, typosquatting, and novelty signals, then produces a deterministic evidence report.
-
Updated
Sep 30, 2026 - Python
Audits AUR PKGBUILD updates before you install: detects structural changes, suspicious commands, typosquatting, and novelty signals, then produces a deterministic evidence report.
A dependency-decision ledger for Node.js & coding agents — every dependency recorded, explained, and reviewable in the PR. Zero runtime deps.
Hands-on study guide for the GH-500: GitHub Advanced Security certification. Covers all 5 exam domains with docs, demos, CodeQL, Dependabot config, and automation scripts.
GitHub Actions GH-500 Certification Study Guide: Complete and up-to-date guide for the GitHub Advanced Security (GHAS) Certification GH-500 Exam. Includes all domains, key concepts, configuration of Secret Scanning, Dependabot, CodeQL, and best practices.
Review dependency update PRs by blast radius: package-lock changes, semver jumps, bin entries, install scripts, and CI risk gates.
Offline semantic dependency review across npm, pnpm, Yarn, uv, Poetry, Cargo, and Go.
Review Dart and Flutter dependency updates for new build hooks, native files, and plugin platform declarations.
GitHub Action for reviewing dependency changes and policy findings in pull requests with Bomly CLI.
Agent skills for developers building NSW Government digital services: Australian Government Style Manual checks, WCAG audits, dependency and pull request review, and more.
Review what a pinned GitHub Action SHA bump actually changes before you approve it.
🤖 Globomantics Robot Fleet Manager - Educational demo with vulnerable dependencies for GitHub Advanced Security training. Tim Warner's Pluralsight Dependency Review course. Learn more: https://pluralsight.com
A Pi.dev skill focused on risk assessment before modifying dependencies in Node.js projects. It helps the agent analyze package-related changes before installing, updating, migrating, or modifying dependencies
GitHub CLI extension for on-demand PR dependency risk review with Dependency Review API first and static local fallback
To associate your repository with the dependency-review topic, visit your repo's landing page and select "manage topics."