Skip to content
#

dependency-scanning

Here are 120 public repositories matching this topic...

High-performance open-source security scanner combining SAST, SCA, Secret Detection, and IaC analysis, built for developers and CI/CD pipelines, using AI for recommendation!

  • Updated Sep 26, 2026
  • Go

GitHub Action that detects the Shai-Hulud 2.0 (Nov 2025) and ChainDrop (Aug 2026) npm supply-chain attacks. Scans dependencies, lockfiles and CI workflows against a daily-updated database of 1,200+ compromised packages, flags malicious install scripts, TruffleHog secret theft and SHA1HULUD runners. SARIF output for GitHub Code Scanning.

  • Updated Sep 26, 2026
  • TypeScript

CLI client (and Golang module) for deps.dev API. Free access to dependencies, licenses, advisories, and other critical health and security signals for open source package versions.

  • Updated Sep 7, 2026
  • Go

Agentic AI for DevSecOps: Transforming Security with GitHub Advanced Security and GitHub Copilot. GitHub Advanced Security - DevSecOps Guidelines - Unified visibility into DevOps security posture. DevSecOps E2E Demos.

  • Updated Jun 29, 2026
  • HTML

Offline, machine-wide Python supply-chain security audit - scan every virtual environment for vulnerable & malicious packages. CVE + typosquat detection, agent/CI-ready JSON. Also a lightweight venv manager.

  • Updated Sep 22, 2026
  • Python

Add this topic to your repo

To associate your repository with the dependency-scanning topic, visit your repo's landing page and select "manage topics."

Learn more