nowfound

Alternatives

Products that do what Deptic does

Scan any GitHub repo.Generate SBOMs & detect CVEs instantly.

  1. 1D0

    deptry 0.14.0 was just released, bringing significant speed improvements: It is now up to 10 times faster than the previous release! For those unfamiliar with deptry; deptry is a command line tool to check for issues with dependencies in a Python project, such as unused or missing dependencies. GitHub: https://github.com/fpgmaas/deptry For some benchmarks of the new release, see the release notes: https://github.com/fpgmaas/deptry/releases/tag/0.14.0 The performance improvement was achieved by leveraging Rust to parse the AST and extract…

    2024 · github.com

  2. 2
    Drata322

    Put SOC 2 compliance on autopilot

    2021

  3. 3
    Arnica97

    Behavior based software supply chain security

    2022

  4. 4CT

    deptrust is a CLI that checks package versions for known vulnerabilities across npm, PyPI, crates.io, Go modules, RubyGems, NuGet, Maven, Packagist, pub.dev, CocoaPods, Hex.pm, Hackage, GitHub Actions, and more. It runs locally as a CLI and as an MCP server. It calls public package registry and OSV APIs directly; there is no hosted deptrust service. I built this because AI coding agents kept suggesting outdated or vulnerable package versions. I kept having to manually tell tools like Claude and Codex to use newer, safer versions. deptrust gives the agent a quick way to verify whether a…

    Jul 2026 · github.com

  5. 5

    The ultimate EVM compatible smart contract analysis tool

    2023

  6. 6SZ

    We're launching SecureBuild: https://securebuild.com — a new way for open source projects and maintainers to earn revenue by partnering with and endorsing our Zero-CVE container images of their project. We’ve spent the last decade at Replicated (https://news.ycombinator.com/item?id=9841243) helping commercial and open source software vendors securely distribute their apps to enterprise environments. During that time, we saw firsthand how hard it is for maintainers to fund their work, and how increasingly demanding enterprises have become when it comes to demonstrable…

    2025 · securebuild.com

  7. 7

    Enforce best practices and security policies on every commit

    2020

  8. 8
    Gitdocs148

    Generate production-ready README files from your GitHub repo

    Dec 2025

  9. 9

    Scan. Score. Decide. One platform for every dependency

    Jun 2026 · deptools.io

  10. 10TT

    Hi everyone, given the recent increase of attacks on the NPM supply chain, I've put together a list of tips and tricks to help developers stay secure on this specific topic: https://github.com/bodadotsh/npm-security-best-practices I'd love for you to check it out, and contribute your own insights and best practices to make this a comprehensive resource for the community. Cheers!

    Sep 2025 · github.com

  11. 11CA

    Hi, my name is Miguel and I am very happy to share what's been months worth of work :) The project has rough edges for sure, but any early feedback, comments or concerns are appreciated! === The Problem === You work on the Security and Operations (SecOps) team in charge of your organization's Software Supply Chain Security. You feel pretty good about the state of things already, your developer teams are signing their commits, deliverables, scanning for vulnerabilities,… Life is good! Then you realize that you are not compliant with the latest security requirements. You get referred to…

    2023 · github.com

  12. 12

    Track vulnerabilities across all your software projects

    Feb 2026

  13. 13

    Your billing says paid. Your app might disagree.

    Jun 2026 · prodverdict.com

  14. 14IB

    I built a GitHub app that detects it in pull requests, notifies or blocks them. Alongside it, I published a Semgrep ruleset for any stage of the CI/CD. I started this after getting frustrated by all the FUD around malicious code - lots of noise, little effort to solve it. Having said that, it's still a major attack vector - a stored RCE, with the codebase itself as the sink. Feedback is appreciated. The app, PRevent - https://github.com/apiiro/PRevent The ruleset: https://github.com/apiiro/malicious-code-ruleset The research:…

    2025 · github.com

  15. 15

    Block bad npm and pip packages. Before they download.

    May 2026 · veln.sh

  16. 16TD

    Trusty - Search for an open source package to understand its trustworthiness based on activity, provenance, and more. Brought to you by the founders of projects such as Kubernetes and Sigstore. Hey, Luke here the CTO of stacklok. This is an early experimental preview of Trusty. We use statistical analysis to observe millions of packages and found that Malware typically follows certain patterns. We found this tool really useful to help understand the packages we our pulling into our software and wanted to share it with others. It's still early in and we have a lot more features that will be…

    2023 · trustypkg.dev

  17. 17

    Configure once, prevent the next compromised package install

    May 2026 · depsguard.com

  18. 18
    Wisec4

    Stop blindly trusting your software supply chain.

    Mar 2026 · wisec.io

  19. 19

    Security Scanner for AI-generated Code

    8d ago · scanity.dev

  20. 20

    Supply chain protection that blocks malware at install

    Jun 2026 · westbayberry.com

  21. 21

    The Autonomous Intelligence Layer for Pull Requests

    Apr 2026 · devlens.xyz

  22. 22

    Get codebase insights without reading every file

    Jan 2026

  23. 23
    Depna2

    Dependency security scans — no repo access, no OAuth

    Jun 2026 · depna.io

  24. 24NR

    I built nblm, a Rust-based toolset to automate Google’s NotebookLM Enterprise API reliably. It aims to replace brittle curl snippets with a stable interface you can use in cron/CI or agentic systems. * Python SDK (type-safe): IDE auto-complete, fewer JSON key typos, fits complex workflows. * Standalone CLI: single fast binary for scripts and pipelines. * Handles auth, batching, retries; you focus on logic. Rust core is fast and memory-safe. * Enterprise API only (consumer NotebookLM isn’t supported). Repo: https://github.com/K-dash/nblm-rs Feedback is welcome—I'm…

    Oct 2025 · github.com

Ranked by how close each launch is in meaning, then by votes. Refine with a description →