Assesses open source software supply chain risk by analyzing dependency vulnerabilities, maintainer trust, license compliance, and detecting typosquatting.
Sponsored
This tool provides a comprehensive solution for evaluating the security and stability of open source software supply chains. It goes beyond simple vulnerability scanning to map complex dependency networks, detect the propagation of CVEs and KEVs, and analyze maintainer risks such as bus factor and potential abandonment. The platform also assesses community health, scores overall supply chain risk using multiple factors, identifies typosquatting attempts, and generates detailed reports to help organizations understand and mitigate their open source security posture.
主な機能
01Detect CVE/KEV vulnerability propagation through dependencies
02Assess maintainer bus factor and abandonment risk
03Detect potential typosquatting packages
04Map OSS dependency network with vulnerability connectivity
05Multi-factor OSS supply chain risk scoring
060 GitHub stars
ユースケース
01Evaluate the trustworthiness and sustainability of open source projects
02Generate comprehensive reports for security auditing, compliance, and strategic planning
03Proactively identify and mitigate security risks in open source dependencies