cyberstars / tools / pwned-deps
pwned-deps
—Lockfile scanner for known-compromised dependencies.
Voir sur GitHub
PythonApache-2.0
Scans npm, PyPI, Maven, Cargo, Go and RubyGems lockfiles for known-compromised package versions by cross-referencing OSV.dev advisories with a curated, Sigstore-signed supply-chain incident feed. Ships CLI, pre-commit and CI/CD integrations for shift-left detection.