An OSS Python dependency scanner for exploited, unmaintained packages
An OSS Python dependency scanner for exploited, unmaintained packages
I built an open source python dependency scanner that will scan and flag packages with known exploit CVEs(CISA's Known Exploited list and FIRST EPSS) and unmaintained packages that have not had a release or commit in 2 years. Theres also claude hook that will make your AI agent not install these type of packages included in this repo. The full mechanism is in the readme of the project, this was just a brief summary.
Share cardActual performance
Launch Intel predictions
Analyze your own launch →Correct prediction on native model
Similar products
Financier, Modeling Compensation Packages with Python
A tool for detecting ABI violations in Python packages
List all the licenses for your pip-installed Python packages.
Deploying Private Python Packages with GitHub and TravisCI
Online Python REPL with every PyPi packages pre-installed
PyPI server for serving Python packages out of GitHub
A curated list of insecure Python packages
Thredded forums are minimalistic and OSS
UPGRADE ALL THE PIP PACKAGES!
Galaxy of Debian packages