> cat /dev/github | grep security-tools
discovered 03 Aug 2026

packj-github-action

★ 10 via github-topic
→ View on GitHub
Packj is a GitHub Action that audits pull requests for malicious or risky open-source dependencies across NPM, PyPI, and RubyGems ecosystems. It employs static, metadata, and dynamic analysis to identify security vulnerabilities, flagging packages based on over 40 risky attributes derived from extensive research on supply chain attacks. Notable features include the ability to integrate seamlessly into GitHub workflows and provide feedback via comments on pull requests when risky dependencies are detected.