Protect against malicious open source packages 🤖
☆1,110Oct 7, 2026Updated this week
Alternatives and similar repositories for vet
Users that are interested in vet are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.☆543Updated this week
- Reference architecture and proof of concept implementation for supply chain security gateway☆23Apr 1, 2023Updated 3 years ago
- Security layer for AI coding agents. Works with Claude Code, Cursor, Windsurf, Gemini CLI, OpenCode, Pi Agent and more.☆171Updated this week
- A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerabilit…☆620Updated this week
- OSV-SCALIBR: A library for Software Composition Analysis☆649Updated this week
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets☆889Aug 31, 2026Updated last month
- Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive files☆234Aug 25, 2026Updated last month
- Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact pro…☆547Updated this week
- A compilation of Software Supply Chain Security resources including initiatives, standards, regulations, organizations, vendors, tooling,…☆151Jan 28, 2024Updated 2 years ago
- Vulnerability scanner written in Go which uses the data provided by https://osv.dev☆11,155Updated this week
- Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, an…☆1,279Updated this week
- Detect secrets + live validation. Map blast radius. Revoke fast. Use the CLI or embed in Rust and Python.☆1,259Updated this week
- 🔎 Static code analysis engine to find security issues in code.☆3,160Updated this week
- poutine, a supply chain vulnerability scanner for build pipelines☆522Updated this week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A vulnerability scanner for container images and filesystems☆12,995Updated this week
- Generate a score for your sbom to understand if it will actually be useful.☆242Aug 13, 2024Updated 2 years ago
- #supply #chain #attack #detection☆678Updated this week
- Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.☆2,758Updated this week
- Enrich SBOMs with data from third party services☆240Sep 21, 2026Updated 2 weeks ago
- Supply Chain Firewall (SCFW) is a tool for preventing the installation of malicious npm and PyPI packages☆398Sep 24, 2026Updated 2 weeks ago
- A universal SBOM representation in protocol buffers☆334Updated this week
- Reconmap is a collaboration-first security operations platform for infosec teams and MSSPs, enabling end‑to‑end engagement management, fr…☆1,000Updated this week
- GuardDog is a CLI tool to Identify malicious PyPI and npm packages☆1,229Updated this week
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- GitHub Attack Toolkit - Extreme Edition - A static analysis and exploit toolkit for GitHub Actions.☆592Oct 2, 2026Updated last week
- Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on p…☆5,906Apr 16, 2026Updated 5 months ago
- Software Supply Chain Security Platform☆422Updated this week
- Scans Software Bill of Materials (SBOMs) for security vulnerabilities☆625Feb 10, 2026Updated 7 months ago
- Open source vulnerability DB and triage service.☆2,966Updated this week
- OpenSSF Scorecard - Security health metrics for Open Source☆5,745Updated this week
- CLI tool and library for generating a Software Bill of Materials from container images and filesystems☆9,658Updated this week
- Analyzes software dependencies across GitHub repositories to identify security vulnerabilities and health risks in your supply chain.☆125May 26, 2026Updated 4 months ago
- Sealed execution environment for GitHub Actions. Stop supply chain attacks dead in their tracks.☆63Updated this week
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Zero shot vulnerability discovery using LLMs☆2,796Feb 6, 2025Updated last year
- Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supp…☆4,269Updated this week
- Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package manager…☆1,085Updated this week
- A security tool that detects malicious packages from external vulnerability feeds and searches for them in your package registries or art…☆72Nov 27, 2025Updated 10 months ago
- Macaron is an extensible supply-chain security analysis framework from Oracle Labs that supports a wide range of build systems and CI/CD …☆210Oct 2, 2026Updated last week
- Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.☆1,451Updated this week
- GitHub App to set and enforce security policies☆1,457Sep 25, 2026Updated 2 weeks ago