{"repo":"safedep/pmg","free":true,"listed":false,"github":"https://github.com/safedep/pmg","clone":"git clone https://github.com/safedep/pmg.git","description":"PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.","language":"Go","stars":494,"topics":["developer-tools","devsecops","malicious-code","npm","open-source","pnpm","supply-chain-security","hacktoberfest"],"license":"Apache-2.0","category":"dev-tools","readme_excerpt":"Package Manager Guard (PMG) Block malicious npm and pip packages before they install. Defense in depth for the package managers you already use. Why PMG? Developers and AI coding agents install packages every day. Each npm install or pip install executes thousands of lines of code that nobody reviews. Recent compromises in popular ecosystems: - Mini Shai-Hulud - 300+ popular packages compromised - litellm 1.82.8 - a popular AI proxy library compromised to exfiltrate credentials - telnyx 4.87.2 - a legitimate telecom SDK hijacked on PyPI - pino-sdk-v2 - a typosquat package disguised as the popular pino logger PMG is free, open source (Apache 2.0), and requires no account or API key. It intercepts every package install and checks it against SafeDep's free community API for known malware before code executes. Install it once, and it covers every npm install , pip install , and poetry add after that. How PMG Works PMG takes a defense in depth approach. Zero config, works across Zsh, Bash, and Fish, and each install passes through the enabled protection layers before code runs, plus an audit trail after. Layer details - Transparent Interception - PMG wraps npm , pip , and other package managers. Developers and AI agents use the same commands. No workflow changes. - Layer 1: Threat Intelligence - PMG checks every package against SafeDep's real-time threat intelligence before install. Known-malicious packages are blocked. No key, no login required. - Layer 2: Policy (Dependency Cool","default_branch":null,"files":null,"tree":[],"storefront":"/r/safedep","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/safedep/pmg/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}