Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs
Zero-config install-time supply-chain hardening for npm, pnpm, yarn, bun, cargo, mise, uv, and bundler.
Instant Rust tools and builds from one command.
A tool for compiling Rust projects, detecting Cargo workspaces, building with cargo, and placing binaries in a conventional dist_rust directory.
gup (Global Updater) — one CLI to scan and update everything installed on your machine across ~130 sources: winget, scoop, chocolatey, npm-g, pnpm-g, yarn-g, bun, pip, pipx, uv, cargo, gem, dotnet tools, composer, helm, kubectl, krew, terraform, pulumi, a
fast running algorithms for .js/.ts written in rust
fast running algorithms for .js/.ts written in rust
A localhost web GUI for managing macOS package managers — Homebrew plus npm, pip, cargo, go, gem, bun and pnpm. Real terminal, command preview, transactional operation queue, CVE scanning, on-demand disk-size & update scans, and an optional AI assistant.
A firewall between AI coding agents and dangerous actions. Blocks hallucinated packages, leaked secrets, destructive commands, and test-subversion.