Protect against malicious open source packages 🤖
☆1,103Aug 27, 2026Updated this week
Alternatives and similar repositories for vet
Users that are interested in vet are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.☆505Updated this week
- Reference architecture and proof of concept implementation for supply chain security gateway☆23Apr 1, 2023Updated 3 years ago
- Security layer for AI coding agents. Works with Claude Code, Cursor, Windsurf, Gemini CLI, OpenCode, Pi Agent and more.☆161Updated this week
- A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerabilit…☆604Updated this week
- OSV-SCALIBR: A library for Software Composition Analysis☆638Updated this week
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets☆882Updated this week
- Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive files☆234Updated this week
- Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact pro…☆546Aug 24, 2026Updated last week
- A compilation of Software Supply Chain Security resources including initiatives, standards, regulations, organizations, vendors, tooling,…☆151Jan 28, 2024Updated 2 years ago
- Vulnerability scanner written in Go which uses the data provided by https://osv.dev☆10,947Updated this week
- Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, an…☆1,258Updated this week
- 🔎 Static code analysis engine to find security issues in code.☆3,006Updated this week
- Detect leaked secrets + live validation. Map blast radius across your stack. Revoke fast. Hundreds of rules.☆1,216Updated this week
- poutine, a supply chain vulnerability scanner for build pipelines☆510Jul 9, 2026Updated last month
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- A vulnerability scanner for container images and filesystems☆12,805Updated this week
- Generate a score for your sbom to understand if it will actually be useful.☆242Aug 13, 2024Updated 2 years ago
- #supply #chain #attack #detection☆675Updated this week
- Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.☆2,740Updated this week
- Enrich SBOMs with data from third party services☆235Updated this week
- Supply Chain Firewall (SCFW) is a tool for preventing the installation of malicious npm and PyPI packages☆391Updated this week
- A universal SBOM representation in protocol buffers☆330Updated this week
- Reconmap is a collaboration-first security operations platform for infosec teams and MSSPs, enabling end‑to‑end engagement management, fr…☆975Updated this week
- GuardDog is a CLI tool to Identify malicious PyPI and npm packages☆1,193Updated this week
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- GitHub Attack Toolkit - Extreme Edition - A static analysis and exploit toolkit for GitHub Actions.☆582Jul 20, 2026Updated last month
- Live validation proxy tool for testing web app vulnerabilities☆883Mar 24, 2026Updated 5 months ago
- Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on p…☆5,760Apr 16, 2026Updated 4 months ago
- Software Supply Chain Security Platform☆419Updated this week
- Scans Software Bill of Materials (SBOMs) for security vulnerabilities☆624Feb 10, 2026Updated 6 months ago
- OpenSSF Scorecard - Security health metrics for Open Source☆5,660Updated this week
- Open source vulnerability DB and triage service.☆2,902Updated this week
- CLI tool and library for generating a Software Bill of Materials from container images and filesystems☆9,479Updated this week
- Sealed execution environment for GitHub Actions. Stop supply chain attacks dead in their tracks.☆58Updated this week
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Analyzes software dependencies across GitHub repositories to identify security vulnerabilities and health risks in your supply chain.☆125May 26, 2026Updated 3 months ago
- Zero shot vulnerability discovery using LLMs☆2,754Feb 6, 2025Updated last year
- Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supp…☆4,157Updated this week
- Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package manager…☆1,056Updated this week
- A security tool that detects malicious packages from external vulnerability feeds and searches for them in your package registries or art…☆72Nov 27, 2025Updated 9 months ago
- Macaron is an extensible supply-chain security analysis framework from Oracle Labs that supports a wide range of build systems and CI/CD …☆210Updated this week
- Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.☆1,388Updated this week