boredchilada/pkgward-oss
oh supply chain my supply chain — a multi-ecosystem package malware scanner for PyPI, npm, crates.io, and Go. Static analysis plus a sandbox detonation engine, with pluggable detection content (open-core; AGPL engine, Apache-2.0 signatures).
GitHub repository with 5 stars and 1 forks.
Language: Python
Topics: crates-io, dependency-confusion, devsecops, go-modules, malware-detection, malware-scanner, npm, package-security, pypi, sandbox