| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container images are supported as the input, and the tool is ideal for integration.
Manage third-party license compliance in your Rollup or Vite builds. Automatically discover every dependency, extract its license info, fail builds with disallowed licenses, and generate a complete “bill-of-materials” in JSON, HTML, CSV or custom formats.
ALNUR — Open-source end-to-end security vulnerability scanner. Detects CVEs, hardcoded secrets, architecture flaws, and port risks across Node.js, Python, PHP, Go, Rust, Java, .NET, Ruby and more
Supply chain security risk scorer for npm, PyPI, Cargo, and Go — behavioral signals that can't be faked
CLI to scan project dependencies and produce a single HTML report
Enterprise security audit plugin for Claude Code. One command (/security-audit) runs a 10-phase audit with auto-remediation and PDF reports. Auto-detects platform type — supports Express, Django, Next.js, Supabase, Firebase, Electron, React Native, WordPress, Stripe, Solidity, and more.
Dependency supply-chain hygiene audit for DeepSeek Harness (dsh): peer-range resolvability, broken dist-tag detection, stale/missing-license/non-registry deps, installed-vs-declared drift. Complements dsh-poison-guard and dsh-plugin-doctor.
List installed Python packages by on-disk size (largest first). Zero dependencies. Ideal for cleaning bloated global/site-packages installs.
Open-source CVE lookup tool for software packages. Check vulnerabilities, CVSS scores, version age, and latest releases across 8 ecosystems using OSV.dev.
MobileSec Agent 是一个面向移动应用的综合安全扫描工具,集成 GitHub Actions CI/CD,基于 AboutSecurity 知识库驱动。覆盖依赖审计、静态代码分析、API 安全测试、移动端安全检查四大阶段,自动生成安全报告并按严重级别告警,帮助团队在开发流程中持续保障移动应用安全。
Audit Composer & npm dependencies for known vulnerabilities and tell whether an available update actually leaves the vulnerable range.
Dependency audit, vulnerability scanning & license compliance. 10 package managers, 100% local, zero telemetry.
Solana-specific dependency auditor. Catches abandoned packages, deprecated SDKs, and malicious packages that npm audit misses.
Scans your project's dependencies and flags zombie packages — abandoned, outdated, or imported-but-unused — before they become a security or maintenance nightmare
PromptAudit
Dependency freshness auditor: days-since-last-release per dependency, flags abandoned packages by policy
Claude Code skill: audits dependencies for vulnerabilities, outdated versions, and unused packages / 脆弱性・古いバージョン・未使用パッケージを依存関係から検出する
🔒 10 Python scripts for security recon: subdomain finder, port scanner, WHOIS lookup, SSL checker, vulnerability scanner. All using free APIs.
Offline A-F supply-chain risk scanner for Bundler Gemfile.lock -- zero dependencies, zero network calls.
Add a description, image, and links to the dependency-audit topic page so that developers can more easily learn about it.
To associate your repository with the dependency-audit topic, visit your repo's landing page and select "manage topics."
| Back | FazBrowse Home | New Git URL |