Skip to content
#

lockfile-analysis

Here are 2 public repositories matching this topic...

Language: All
Filter by language

A lightweight CLI focused on security & visibility of dependencies, inspecting Node.js projects for install/prepare hooks and binaries. Find out what dependencies are running scripts during install, why they are present, and what binaries they expose.

  • Updated Mar 5, 2026
  • TypeScript

Shai-Hulud/ChainDrop npm worm scanner — 220 tests, zero deps, cross-platform. Detects 416 poisoned packages: lockfile analysis, SHA-256 hashes, content markers, credential audit, persistence. ReDoS-safe, thread-safe, SARIF output. Production-ready supply-chain defense.

  • Updated Aug 8, 2026
  • Python

Improve this page

Add a description, image, and links to the lockfile-analysis topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the lockfile-analysis topic, visit your repo's landing page and select "manage topics."

Learn more