Protect against malicious open source packages 🤖
☆1,096Jul 30, 2026Updated last week
Alternatives and similar repositories for vet
Users that are interested in vet are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.☆488Jul 28, 2026Updated last week
- Reference architecture and proof of concept implementation for supply chain security gateway☆23Apr 1, 2023Updated 3 years ago
- Security layer for AI coding agents. Works with Claude Code, Cursor, Windsurf, Gemini CLI, OpenCode, Pi Agent and more.☆153Jul 27, 2026Updated 2 weeks ago
- A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerabilit…☆596Updated this week
- OSV-SCALIBR: A library for Software Composition Analysis☆632Updated this week
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets☆880Mar 28, 2025Updated last year
- Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive files☆233Apr 17, 2026Updated 3 months ago
- Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact pro…☆544Updated this week
- A compilation of Software Supply Chain Security resources including initiatives, standards, regulations, organizations, vendors, tooling,…☆150Jan 28, 2024Updated 2 years ago
- Vulnerability scanner written in Go which uses the data provided by https://osv.dev☆10,799Updated this week
- Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, an…☆1,242Updated this week
- 🔎 Static code analysis engine to find security issues in code.☆2,902Updated this week
- Detect leaked secrets + live validation. Map blast radius across your stack. Revoke fast. 1,000+ rules.☆1,193Updated this week
- poutine, a supply chain vulnerability scanner for build pipelines☆503Jul 9, 2026Updated last month
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- A vulnerability scanner for container images and filesystems☆12,711Updated this week
- Generate a score for your sbom to understand if it will actually be useful.☆242Aug 13, 2024Updated last year
- #supply #chain #attack #detection☆671Updated this week
- Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.☆2,716Aug 3, 2026Updated last week
- Enrich SBOMs with data from third party services☆234Updated this week
- Supply Chain Firewall (SCFW) is a tool for preventing the installation of malicious npm and PyPI packages☆381Jul 20, 2026Updated 3 weeks ago
- A universal SBOM representation in protocol buffers☆327Updated this week
- Reconmap is a collaboration-first security operations platform for infosec teams and MSSPs, enabling end‑to‑end engagement management, fr…☆972Updated this week
- GuardDog is a CLI tool to Identify malicious PyPI and npm packages☆1,179Updated this week
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- GitHub Attack Toolkit - Extreme Edition - A static analysis and exploit toolkit for GitHub Actions.☆568Jul 20, 2026Updated 3 weeks ago
- Live validation proxy tool for testing web app vulnerabilities☆879Mar 24, 2026Updated 4 months ago
- Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on p…☆5,742Apr 16, 2026Updated 3 months ago
- Software Supply Chain Security Platform☆413Updated this week
- Scans Software Bill of Materials (SBOMs) for security vulnerabilities☆624Feb 10, 2026Updated 6 months ago
- OpenSSF Scorecard - Security health metrics for Open Source☆5,624Updated this week
- Open source vulnerability DB and triage service.☆2,878Updated this week
- CLI tool and library for generating a Software Bill of Materials from container images and filesystems☆9,373Updated this week
- Sealed execution environment for GitHub Actions. Stop supply chain attacks dead in their tracks.☆56Updated this week
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Analyzes software dependencies across GitHub repositories to identify security vulnerabilities and health risks in your supply chain.☆125May 26, 2026Updated 2 months ago
- Zero shot vulnerability discovery using LLMs☆2,729Feb 6, 2025Updated last year
- Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supp…☆4,094Updated this week
- Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package manager…☆1,034Updated this week
- A security tool that detects malicious packages from external vulnerability feeds and searches for them in your package registries or art…☆70Nov 27, 2025Updated 8 months ago
- Macaron is an extensible supply-chain security analysis framework from Oracle Labs that supports a wide range of build systems and CI/CD …☆210Updated this week
- Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.☆1,369Updated this week