{"repo":"arnica/depsguard","free":true,"listed":false,"github":"https://github.com/arnica/depsguard","clone":"git clone https://github.com/arnica/depsguard.git","description":"Harden your package manager configs against supply chain attacks.","language":"Rust","stars":384,"topics":["dependencies","npm","pnpm","software-supply-chain-security","uv","cli","cooldown","devsecops","package-manager","rust"],"license":"MIT","category":"cli-tools","readme_excerpt":"depsguard Guard your dependencies against supply chain attacks. Single static binary, zero Rust crate dependencies. By [arnica] Table of contents - Overview - Install - Usage - What gets checked - Config file locations - Urgent security fix - Backups and restore - How it works - Troubleshooting - Help & feedback - Guides - See also - License Overview DepsGuard looks for npm , pnpm , yarn , bun , uv , pip , poetry , and aube on your machine, reads their config files, compares them to recommended supply-chain settings, and can apply fixes interactively . It also scans for Renovate and Dependabot configs in your repos. It never runs package installs; it only edits config files you approve, and it writes backups before any change. Key features - Interactive TUI: scan, review, toggle fixes, apply - scan subcommand for read-only reporting - restore subcommand to pick a backup and roll back a file - Cross-platform: Linux, macOS, Windows - No bundled third-party Rust crates (stdlib + small amount of platform FFI for the terminal) Tech stack Area Details ------ --------- Language Rust (MSRV 1.74 , see Cargo.toml ) CLI / TUI src/main.rs , src/ui.rs , src/term.rs Config logic src/manager.rs , src/fix.rs Website Static site under docs/ (separate from the binary) Install Prebuilt binaries Each GitHub Release includes archives for: - Linux: x86 64 (glibc), x86 64 (musl), aarch64 (glibc) - macOS: Intel and Apple Silicon - Windows: x86 64 ZIP containing depsguard.exe Download the archive for","default_branch":null,"files":null,"tree":[],"storefront":"/r/arnica","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/arnica/depsguard/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}