{"repo":"mkbhardwas12/pwned-deps","free":true,"listed":false,"github":"https://github.com/mkbhardwas12/pwned-deps","clone":"git clone https://github.com/mkbhardwas12/pwned-deps.git","description":"Lockfile-first scanner for compromised npm/PyPI/Maven/Cargo/Go/RubyGems packages — OSV + curated extras feed, SLSA L3, locked-container CI","language":"Python","stars":164,"topics":["cargo","cli","dependency-scanner","devsecops","go","lockfile","maven","npm","osv","pypi"],"license":"Apache-2.0","category":"cli-tools","readme_excerpt":"pwned-deps Drop your lockfile in. Get a red/green answer in 5 seconds. A multi-ecosystem scanner for compromised package versions — account hijacks, typosquats, dependency-confusion, retroactively trojanised releases — across npm, PyPI, Maven, Cargo, Go, RubyGems. Re-render the demo any time the CLI's output changes: make demo-gif (Docker; no host installs). Table of contents - At a glance - Architecture - Why this exists - Campaigns the bundled feed already covers - A worked example: Mini Shai-Hulud (April 29, 2026) - Install - See it in action - Benchmark - Quick usage - Watch mode (the recurring-value workflow) - Supported ecosystems - Real-world scenarios this is built for - CI integration - GitHub Actions (one line) - Plain workflow step (no action wrapper) - Sticky PR comment (the bot workflow) - Static HTML dashboard (org-wide visibility) - pre-commit - GitLab CI - Output formats - Threat model - Verify a release with SLSA provenance - Comparison - Where each tool is the right answer - FAQ - Contributing - Maintenance - Changelog - Security policy - License - Maintainer pwned-deps is a Python CLI that takes one or more developer lockfiles ( package-lock.json , pnpm-lock.yaml , yarn.lock , requirements.txt , Pipfile.lock , poetry.lock , uv.lock , Cargo.lock , go.sum , pom.xml , Gemfile.lock ) and tells you, in seconds, whether you've installed a package version that's publicly flagged as compromised — supply-chain malware, abandoned-and-hijacked packages, retroactively ","default_branch":null,"files":null,"tree":[],"storefront":"/r/mkbhardwas12","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/mkbhardwas12/pwned-deps/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}