{"repo":"safedep/vet","free":true,"listed":false,"github":"https://github.com/safedep/vet","clone":"git clone https://github.com/safedep/vet.git","description":"Protect against malicious open source packages 🤖","language":"Go","stars":1097,"topics":["devsecops","security","supply-chain-security","policy-as-code","software-composition-analysis","golang","npm","pypi","rubygems","static-analysis"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"Quick Start • Documentation • Community --- [!NOTE] vet also runs in the cloud. Point it at your GitHub repositories and get continuous scanning, malware detection, and policy enforcement without managing any infrastructure. See SafeDep Cloud for the end-to-end software supply chain security platform. Why vet? 70-90% of modern software is open source code — how do you know it's safe? Traditional SCA tools drown you in CVE noise. vet takes a different approach: - Shadow AI discovery — Discover AI tool usage signals across various tools and configurations - Catch malware before it ships — Zero-day detection through static and dynamic behavioral analysis (requires SafeDep Cloud access) - Cut through vulnerability noise — Analyzes actual code usage to surface only the risks that matter - Enforce policy as code — Express security, license, and quality requirements as CEL expressions - CI/CD integration — Zero-config security guardrails in CI/CD Free for open source. Hosted SaaS available at SafeDep. Quick Start Install in seconds: or download a pre-built binary Get started immediately: Architecture vet follows a pipeline architecture: readers ingest package manifests from diverse sources (directories, repositories, container images, SBOMs), enrichers augment each package with vulnerability, malware, and scorecard data from SafeDep Cloud, the CEL policy engine evaluates security policies against enriched data, and reporters produce actionable output in formats like SARIF, JSON, and","default_branch":null,"files":null,"tree":[],"storefront":"/r/safedep","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/safedep/vet/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}