pwned-deps
Scans lockfiles for npm/PyPI/Maven/Cargo/Go packages flagged as compromised.
Desktopfree
pwned-deps is an open-source CLI tool that scans developer lockfiles across npm, PyPI, Maven, Cargo, Go, and RubyGems for package versions publicly flagged as compromised, hijacked, or trojanized. It combines the OSV.dev database with a curated feed of named supply-chain incidents and integrates into CI pipelines. Built for application developers, SREs, and AppSec responders during active incidents.
Categories
SecuritySupply Chain SecurityDependency Scanning
Something wrong with this listing — dead link, not a real product, wrong info?

