safely install npm packages by auditing them pre-install stage
-
Updated
Aug 25, 2026 - JavaScript
safely install npm packages by auditing them pre-install stage
The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic core, no API key needed, JSON and SARIF output.
The open standard for proving any file is real, unaltered and sealed
Docker Scout GitHub Action
Runtime Security Solution for your CI/CD Pipeline
Security scanner MCP server for AI coding agents. Prompt injection firewall, package hallucination detection (4.3M+ packages), 1000+ vulnerability rules with AST & taint analysis, auto-fix.
DSH plugin - framework upgrade safety & plugin gating: contract pre-check, rollback point, auto-rollback on failure, evidence-based auto-disable; plus a multi-source plugin market. Unofficial. | DSH 插件:框架升级安全 + 插件门控——升级前契约预检、回滚点、失败自动回滚、���确证证据才自动禁用;另带多源插件市场。非官方社区项目。
Audit your GitHub Actions workflow runs to see exactly which Actions were downloaded
scans popular packages and alerts in cases there is suspicion of an account takeover
Secure GitHub actions with 1 line of code
Identify bridges from JS to Native or JS to WASM in V8 embedders
Automated OSS maintenance evidence log. Tracks 1.6M npm downloads/week across 7 packages. Self-updating every 6h via GitHub Actions.
A Git-native dependency admission controller. Evaluates trust signals on every dependency change and blocks commits or builds when packages fail your team's policy. Pre-commit hook + CI gate with built-in approval workflow.
Supply-chain attack scanner for the agent era. Triage in 30s with `npx patient-zero`, block malicious installs before postinstall runs, or drop into CI as a GitHub Action. Covers npm + Python + MCP agent configs. Free, MIT, no signup, no telemetry.
Kernel-level execution records for GitHub Actions
Real-time npm/PyPI supply-chain threat detection. Behavioral chain analysis, AST scanning, IOC feeds, and compound scoring engine.
A zero-dependency Node.js CLI tool that scans package-lock.json for suspicious patterns that indicate supply chain attacks.
Pre-install security for AI agents, npm packages, and MCP servers. Zero-dep local static analysis; normal scans never execute package code.
🛡️ Zero-Trust npm wrapper for secure package installations. Deep AST & Shadow Execution detection for Zero-Day threats. Active Honey-Trap defense to block credential exfiltration.
To associate your repository with the supply-chain-security topic, visit your repo's landing page and select "manage topics."