← Back to match
pwned-deps
Scans lockfiles for npm/PyPI/Maven/Cargo/Go packages flagged as compromised.
Desktopfree
pwned-deps is an open-source CLI tool that scans developer lockfiles across npm, PyPI, Maven, Cargo, Go, and RubyGems for package versions publicly flagged as compromised, hijacked, or trojanized. It combines the OSV.dev database with a curated feed of named supply-chain incidents and integrates into CI pipelines. Built for application developers, SREs, and AppSec responders during active incidents.
Categories
SecuritySupply Chain SecurityDependency Scanning

