discovered 03 Aug 2026
packj-github-action
→ View on GitHubPackj is a GitHub Action that audits pull requests for malicious or risky open-source dependencies across NPM, PyPI, and RubyGems ecosystems. It employs static, metadata, and dynamic analysis to identify security vulnerabilities, flagging packages based on over 40 risky attributes derived from extensive research on supply chain attacks. Notable features include the ability to integrate seamlessly into GitHub workflows and provide feedback via comments on pull requests when risky dependencies are detected.