supply-chain-scan
v0.1.0npm· JavaScriptMorning supply-chain safety scan for npm, PyPI and Docker projects — known-malicious packages + CVEs + freshly-published deps + release-cooldown/digest pinning. Zero dependencies, cross-platform, one command.
The verdict
Maintained. Maintained, actively maintained.
Live from the npm registry · derived rules, not AI
How it scores
MaintenanceHealthy
PopularityUnknown
SecurityClean
LicensePermissive
DepsZero deps
Maintenance
Last published this month.
Popularity
Download count unavailable.
Security
No known advisories for this version (OSV).
License
MIT
Dependencies
No runtime dependencies
Recent releases
- 0.1.0this month