discovered 03 Aug 2026
pwned-deps
→ View on GitHub`pwned-deps` is a multi-ecosystem CLI tool designed for quickly identifying compromised package versions in developer lockfiles, such as those used in npm, PyPI, Maven, Cargo, Go, and RubyGems. It provides rapid assessments—flagging risks like supply-chain malware and hijacked packages—by leveraging data from public APIs and curated feeds, with output options including terminal reports, JSON, and SARIF for integration into code scanning platforms. Key features include support for various lockfile formats, one-shot scans, and continuous monitoring modes.