nowfound

Alternatives

Products that do what Depna does

Dependency security scans — no repo access, no OAuth

  1. 1
    DepsHub360

    Update dependencies using AI

    2024

  2. 2

    Find every EOL dependency in your stack. Free. In 5 minutes.

    Apr 2026 · herodevs.com

  3. 3

    Find outdated deps and CVEs across 8 ecosystems in VS Code

    Jun 2026 · scanreq.com

  4. 4AK

    I'm a software engineer who keeps getting pulled into DevOps no matter how hard I try to escape it. I recently moved into a Lead DevOps Engineer role writing tooling to automate a lot of the pain away. On my own time outside of work, I built Artifact Keeper — a self-hosted artifact registry that supports 45+ package formats. Security scanning, SSO, replication, WASM plugins — it's all in the MIT-licensed release. No enterprise tier. No feature gates. No surprise invoices. Your package managers — pip, npm, docker, cargo, helm, go, all of them — talk directly to it using their native…

    Feb 2026 · github.com

  5. 5NI

    Our package registry ecosystem has a serious problem... and not just npm. People are aware of this but maybe this will make them a bit more aware

    2022 · github.com

  6. 6

    An open source security scanner for Visual Studio Code

    2020

  7. 7
    DepsAudit119

    Package monitoring you didn't know you needed

    2024

  8. 8
    qsa.sh 107

    External security scan of your own IP, in your terminal

    Jul 2026 · qsa.sh

  9. 9SN

    This past quarter has been awash with sophisticated npm supply chain attacks like [Shai-Hulud](https://www.cisa.gov/news-events/alerts/2025/09/23/widesprea...() and the [Chalk/debug Compromise](https://www.wiz.io/blog/widespread-npm-supply-chain-attack-b...). This CLI helps protect users from recently compromised packages by only downloading packages that have been public for a while (default is 90 days or older). Install: npm install -g @dendronhq/safe-npm Usage: safe-npm install react@^18 lodash How it works: - Queries…

    Nov 2025 · github.com

  10. 10

    Block bad npm and pip packages. Before they download.

    May 2026 · veln.sh

  11. 11SZ

    We're launching SecureBuild: https://securebuild.com — a new way for open source projects and maintainers to earn revenue by partnering with and endorsing our Zero-CVE container images of their project. We’ve spent the last decade at Replicated (https://news.ycombinator.com/item?id=9841243) helping commercial and open source software vendors securely distribute their apps to enterprise environments. During that time, we saw firsthand how hard it is for maintainers to fund their work, and how increasingly demanding enterprises have become when it comes to demonstrable…

    2025 · securebuild.com

  12. 12IB

    Linux Foundation survey says 70-90% of modern software constitute OSS code. Yet we are stuck with tools that scan only for vulnerabilities in 3rd party libraries and that too with high degree of false positives. I built `vet` for policy and data driven analysis of 3rd party packages that goes beyond only vulnerability and allows codifying organisational policies related to OSS consumption. https://github.com/safedep/vet Looking forward to feedback and suggestions from HN :)

    2023 · github.com

  13. 13CT

    deptrust is a CLI that checks package versions for known vulnerabilities across npm, PyPI, crates.io, Go modules, RubyGems, NuGet, Maven, Packagist, pub.dev, CocoaPods, Hex.pm, Hackage, GitHub Actions, and more. It runs locally as a CLI and as an MCP server. It calls public package registry and OSV APIs directly; there is no hosted deptrust service. I built this because AI coding agents kept suggesting outdated or vulnerable package versions. I kept having to manually tell tools like Claude and Codex to use newer, safer versions. deptrust gives the agent a quick way to verify whether a…

    Jul 2026 · github.com

  14. 14IB
  15. 15

    Configure once, prevent the next compromised package install

    May 2026 · depsguard.com

  16. 16TD

    Trusty - Search for an open source package to understand its trustworthiness based on activity, provenance, and more. Brought to you by the founders of projects such as Kubernetes and Sigstore. Hey, Luke here the CTO of stacklok. This is an early experimental preview of Trusty. We use statistical analysis to observe millions of packages and found that Malware typically follows certain patterns. We found this tool really useful to help understand the packages we our pulling into our software and wanted to share it with others. It's still early in and we have a lot more features that will be…

    2023 · trustypkg.dev

  17. 17

    Free repo risk scanner: AI copilot, DORA metrics & CVEs

    May 2026 · reporisk-radar-af82e8.gitlab.io

  18. 18

    Offline Python CVE vulnerability scanner...

    Jul 2026 · github.com

  19. 19

    Free, anonymous dependency & code security scanning

    12d ago · depwarden.in

  20. 20

    Your dependencies are your biggest attack surface.

    Apr 2026

  21. 21

    Scan your repo and get secure code in 1 click.

    May 2026 · prev-ent.com

  22. 22IB

    I built a GitHub app that detects it in pull requests, notifies or blocks them. Alongside it, I published a Semgrep ruleset for any stage of the CI/CD. I started this after getting frustrated by all the FUD around malicious code - lots of noise, little effort to solve it. Having said that, it's still a major attack vector - a stored RCE, with the codebase itself as the sink. Feedback is appreciated. The app, PRevent - https://github.com/apiiro/PRevent The ruleset: https://github.com/apiiro/malicious-code-ruleset The research:…

    2025 · github.com

  23. 23
    Opviva10

    It proves your app's security holes, then fixes them

    Jul 2026 · opviva.com

  24. 24VS

Ranked by how close each launch is in meaning, then by votes. Refine with a description →