discovered 03 Aug 2026
still_active
→ View on GitHub`still_active` is a dependency auditing tool that evaluates the maintenance status of packages across multiple ecosystems, including Ruby, npm, PyPI, Cargo, and more, by identifying archived repositories, lack of recent releases, and vulnerabilities that remain unpatched. Its notable features include last-commit activity checks, OpenSSF scorecard evaluations, and detection of “poison-pill” dependencies that may hinder security updates. This tool serves as a complementary addition to existing package management solutions by proactively highlighting risks associated with outdated or abandoned dependencies.