Protect against malicious open source packages 🤖
☆1,105Sep 16, 2026Updated this week
Alternatives and similar repositories for vet
Users that are interested in vet are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.☆513Updated this week
- Security layer for AI coding agents. Works with Claude Code, Cursor, Windsurf, Gemini CLI, OpenCode, Pi Agent and more.☆162Aug 30, 2026Updated 3 weeks ago
- Generate xBOMs enriched with AI, SaaS, Crypto and more using Static Code Analysis☆37Jan 22, 2026Updated 7 months ago
- A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerabilit…☆610Updated this week
- OSV-SCALIBR: A library for Software Composition Analysis☆644Updated this week
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets☆887Aug 31, 2026Updated 2 weeks ago
- Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive files☆234Aug 25, 2026Updated 3 weeks ago
- Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact pro…☆546Updated this week
- A compilation of Software Supply Chain Security resources including initiatives, standards, regulations, organizations, vendors, tooling,…☆151Jan 28, 2024Updated 2 years ago
- Vulnerability scanner written in Go which uses the data provided by https://osv.dev☆11,056Updated this week
- Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, an…☆1,272Aug 31, 2026Updated 2 weeks ago
- Detect leaked secrets + live validation. Map blast radius across your stack. Revoke fast. Hundreds of rules.☆1,236Updated this week
- 🔎 Static code analysis engine to find security issues in code.☆3,092Updated this week
- poutine, a supply chain vulnerability scanner for build pipelines☆518Jul 9, 2026Updated 2 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- A vulnerability scanner for container images and filesystems☆12,904Updated this week
- Generate a score for your sbom to understand if it will actually be useful.☆242Aug 13, 2024Updated 2 years ago
- #supply #chain #attack #detection☆677Updated this week
- Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.☆2,745Updated this week
- Enrich SBOMs with data from third party services☆240Aug 28, 2026Updated 3 weeks ago
- Supply Chain Firewall (SCFW) is a tool for preventing the installation of malicious npm and PyPI packages☆394Updated this week
- A universal SBOM representation in protocol buffers☆333Updated this week
- Reconmap is a collaboration-first security operations platform for infosec teams and MSSPs, enabling end‑to‑end engagement management, fr…☆982Updated this week
- GuardDog is a CLI tool to Identify malicious PyPI and npm packages☆1,210Updated this week
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- GitHub Attack Toolkit - Extreme Edition - A static analysis and exploit toolkit for GitHub Actions.☆590Jul 20, 2026Updated last month
- Live validation proxy tool for testing web app vulnerabilities☆886Mar 24, 2026Updated 5 months ago
- Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on p…☆5,790Apr 16, 2026Updated 5 months ago
- Software Supply Chain Security Platform☆421Updated this week
- Scans Software Bill of Materials (SBOMs) for security vulnerabilities☆624Feb 10, 2026Updated 7 months ago
- Open source vulnerability DB and triage service.☆2,931Updated this week
- OpenSSF Scorecard - Security health metrics for Open Source☆5,697Updated this week
- CLI tool and library for generating a Software Bill of Materials from container images and filesystems☆9,583Updated this week
- Analyzes software dependencies across GitHub repositories to identify security vulnerabilities and health risks in your supply chain.☆125May 26, 2026Updated 3 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Sealed execution environment for GitHub Actions. Stop supply chain attacks dead in their tracks.☆61Updated this week
- Zero shot vulnerability discovery using LLMs☆2,774Feb 6, 2025Updated last year
- Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supp…☆4,222Updated this week
- Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package manager…☆1,074Updated this week
- A security tool that detects malicious packages from external vulnerability feeds and searches for them in your package registries or art…☆72Nov 27, 2025Updated 9 months ago
- Macaron is an extensible supply-chain security analysis framework from Oracle Labs that supports a wide range of build systems and CI/CD …☆210Updated this week
- Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.☆1,429Updated this week