a package manager for JavaScript
Effortlessly bundle and publish npm packages from the command line with @packtory/cli.
Resolve NPM package aliases
semantic-release plugin to publish lerna monorepo packages to npm
Read, write, and convert npm (v1, v2) and yarn (classic and berry) lockfiles in any directions with reasonable losses.
Transform file: dependencies to npm versions for publishing
Supply-chain threat detection & response for npm & PyPI/Python
Private NPM Registry for Enterprise
Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs
Zero-config install-time supply-chain hardening for npm, pnpm, yarn, bun, cargo, mise, uv, and bundler.
Supply-chain security audit for npm packages, as an MCP tool and a pay-per-call x402 endpoint. Cross-references known CVE/GHSA advisories (OSV.dev) and detects typosquatting, malicious install scripts, token/credential exfiltration and other red flags BEF
Claim a brand-new npm name so a Trusted Publisher can be configured for it (workaround for npm/cli#8544).
LPM CLI native binary installer for npm
Filters npm audit JSON output using project-local audit exclusions
Detect the package manager (npm, yarn, pnpm, bun) a project prefers: user-agent, lockfile, packageManager field, corepack, and Windows-safe command resolution.
npm / node module to transfer dependency information to TrustSource server.
Local-first CLI that blocks risky npm, pnpm, and bun installs before they run. Open source.