FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

dependency-security · GitHub Topics · GitHub

#

dependency-security

Here are 51 public repositories matching this topic...

CLI client (and Golang module) for deps.dev API. Free access to dependencies, licenses, advisories, and other critical health and security signals for open source package versions.

  • Updated Aug 24, 2026
  • Go

Dependency safety gate for Claude Code & Codex CLI — OSV pre-approval, npm lockfile-closure enforcement, and auto-rollback. Local, zero runtime deps.

  • Updated Aug 20, 2026
  • Shell

Pin your 3rd Party Github Actions and Docker Images dependencies.

  • Updated Mar 15, 2025
  • Go

Educational dependency scanner built in pure Go—parse go.mod and go.sum, inspect direct and indirect modules, query OSV for vulnerabilities, and summarize licenses.

  • Updated Aug 16, 2025
  • Go

Local-first npm supply-chain security scanner: static + optional LLM analysis, CLI/CI gates, desktop app, and AI-agent skills.

  • Updated Aug 27, 2026
  • TypeScript

Secure your dependencies before they land in production. secure-packages audits package source, reviews new-version diffs, and blocks risky updates in CI/CD, starting with PyPI.

  • Updated Mar 30, 2026
  • Rust

🛡️ AI-powered vulnerability scanner that automatically detects, analyzes, and fixes security issues in npm packages with intelligent code transformations. Supports GitHub Actions, CLI, Docker, and VS Code integration with Microsoft Teams notifications.

  • Updated Sep 29, 2025
  • TypeScript

Sentinel Package Manager blocks compromised packages BEFORE installation, preventing malicious code execution. Features: Pre-install blocking, command interception (npm/yarn/pnpm/bun), 795+ blacklist (Shai-Hulud), real-time checks (OSV/GitHub/Snyk), zero dependencies, auto-updates. Counters supply chain attacks.

  • Updated Dec 2, 2025
  • JavaScript

Ubel is a fast, cross‑ecosystem security engine that resolves dependencies, generates PURLs, scans them through OSV.dev, and enforces security policies during installation to prevent supply-chain attacks. It works with: PyPI (via ubel-pip), npm (via ubel-npm),and Linux distributions (Ubuntu-based, Debian-based, RHEL, AlmaLinux).

  • Updated Aug 13, 2026
  • JavaScript

Supply-chain policy gate for npm, pnpm, yarn, and PyPI. Blocks risky dependencies before install.

  • Updated Aug 3, 2026
  • Rust

90-tool MCP server for software supply chain security — OSV, GHSA, NVD, EPSS, CISA KEV, npm, PyPI, crates.io, RubyGems, NuGet, Packagist, Go, deps.dev, Scorecard, Rekor, ClearlyDefined, Repology, typosquatting detection

  • Updated Aug 12, 2026
  • TypeScript

Runtime dependency security sensor that uses eBPF to attribute Linux syscalls to packages and alert on behavior drift.

  • Updated Jul 22, 2026
  • C

👻 Stop installing packages that don't exist. When AI hallucinates names like "flask-gpt-helper", attackers register them as malware. Phantom Guard detects slopsquatting attacks across PyPI, npm & crates.io before you install.

  • Updated Mar 6, 2026
  • Python

A drop-in npm/pip that never runs install scripts. Deny-by-default supply-chain security for npm & PyPI.

  • Updated Jun 11, 2026
  • Rust

A security harness for AI coding agents. Supply chain, command scope, config integrity. Build specifications.

  • Updated Aug 5, 2026
  • Shell

Block npm/npx/yarn in Claude Code with a skill + PreToolUse hook. Use pnpm instead. Defense against Shai-Hulud-style npm supply-chain attacks.

  • Updated Jul 11, 2026
  • JavaScript

Long-Term Support (LTS) security fork of urllib3 with backported CVE fixes for Python 3.7 and 3.8.

  • Updated Feb 23, 2026
  • Python

Package Firewall — self-hosted supply chain security for macOS. Intercepts npm/pip/cargo/yarn in ALL shells including AI agents. 4 vuln sources (OSV + GHSA + deps.dev + CISA KEV). Zero telemetry.

  • Updated Apr 1, 2026
  • TypeScript

Multi-gate open source supply chain trust validation pipeline with zero-day CVE expedited lane

  • Updated Jun 25, 2026
  • Python

Improve this page

Add a description, image, and links to the dependency-security topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the dependency-security topic, visit your repo's landing page and select "manage topics."

Learn more


Back | FazBrowse Home | New Git URL