
rev-dep
Dependency analysis and optimization toolkit for modern JavaScript and TypeScript codebases. Enforce dependency graph hygiene and remove unused code…

Dependency analysis and optimization toolkit for modern JavaScript and TypeScript codebases. Enforce dependency graph hygiene and remove unused code…

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

Buildless dependency auditor that scans 10 ecosystems offline, reporting CVEs prioritized by CISA KEV and EPSS, EOL packages, licenses, committed…

Audits Python environments, requirements files and dependency trees for known security vulnerabilities, and can automatically fix them

Automated dependency security layer for AI coding assistants that audits packages for CVEs, typosquats, abandonment, version-age issues, and hash…

StepSecurity owned org for analyzing compromised packages

Malicious package & supply-chain intelligence

Detect CVE-2026-45321 Mini Shai-Hulud supply chain compromise — scans for 170 npm + 2 PyPI poisoned packages across TanStack, Mistral AI, UiPath,…

🛡️ One-command scanner for CVE-2026-45321 — TanStack npm supply-chain attack

A Git-native dependency admission controller. Evaluates trust signals on every dependency change and blocks commits or builds when packages fail your…

DepAlert is an open-source security gate for your CI/CD pipeline. It analyzes SBOMs against malware intelligence data and quickly tells you whether…

CVE-2025-55182 Detector. Find which of your GitHub repositories are exposed to the critical React/Next.js RCE vulnerability and generate a clean…

GitHub Action for Heisenberg SSC

The dependency-check repository has moved:

LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and…

Analyze any snippet, file, or repository to detect possible security flaws such as secret in code, open source vulnerability, code security,…