Matchboxmatchbox
← Back to match

pwned-deps

Scans lockfiles for npm/PyPI/Maven/Cargo/Go packages flagged as compromised.

Desktopfree

pwned-deps is an open-source CLI tool that scans developer lockfiles across npm, PyPI, Maven, Cargo, Go, and RubyGems for package versions publicly flagged as compromised, hijacked, or trojanized. It combines the OSV.dev database with a curated feed of named supply-chain incidents and integrates into CI pipelines. Built for application developers, SREs, and AppSec responders during active incidents.

Categories
SecuritySupply Chain SecurityDependency Scanning

Full match profile

Behind the summary, Matchbox keeps a richer profile of pwned-deps - the signals our matcher actually reads to decide when to surface it. It stays private; claim the listing to see and control it.

  • Problem & pain-point mapping
  • Who we surface it to (audience fit)
  • What it's a strong alternative to
  • Trust & credibility signals

Try Matchbox with your own problem

Describe what is not working - we’ll show you whether pwned-deps (or something else) actually fits.