Skip to content
#

dependency-security

Here are 8 public repositories matching this topic...

Sentinel Package Manager blocks compromised packages BEFORE installation, preventing malicious code execution. Features: Pre-install blocking, command interception (npm/yarn/pnpm/bun), 795+ blacklist (Shai-Hulud), real-time checks (OSV/GitHub/Snyk), zero dependencies, auto-updates. Counters supply chain attacks.

  • Updated Dec 2, 2025
  • JavaScript

A local-first application and supply-chain security engine spanning dependency security, install-time enforcement, host inventory, secrets, license compliance, SAST/malware analysis, cloud posture, easm, compliance frameworks mapping, kev, epss, and CI/CD gating.

  • Updated Oct 11, 2026
  • JavaScript

A dependency supply-chain shield for npm — quarantine, statically scan, and diff dependencies to stop malicious packages before they run. Zero runtime dependencies. Benchmarked against 10 real-world attacks (XZ, Shai-Hulud, Nx, tj-actions, Polyfill, Solana, Ledger, Ultralytics, event-stream, node-ipc).

  • Updated Jun 6, 2026
  • JavaScript

Stop AI coding agents (Claude Code, Codex, Gemini CLI, Cursor) from installing npm/PyPI packages that don't exist — slopsquatting guard + MCP API for version-exact checks

  • Updated Oct 3, 2026
  • JavaScript

Add this topic to your repo

To associate your repository with the dependency-security topic, visit your repo's landing page and select "manage topics."

Learn more