nowfound

Alternatives

Products that do what Find out if you're using any modules involved in the “kik NPM incident” does

  1. 1KC
  2. 2SW
  3. 3TS
  4. 4KD

    I've built this to make it easy to host your own infra for lightweight VMs at large scale. Intended for exec of AI-generated code, for CICD runners, or for off-chain AI DApps. Mainly to avoid Docker-in-Docker dangers and mess. Super easy to use with CLI / Python SDK, friendly to AI engs who usually don't like to mess with VM orchestration and networking too much. Defense-in-depth philosophy. Would love to get feedback (and contributors: clear & exciting roadmap!), thx

    Oct 2025 · github.com

  5. 5
    Ask Ellie173

    Turn Slack messages into GitHub, Jira, or Linear tickets

    Feb 2026 · entelligence.ai

  6. 6ET
  7. 7NI

    Our package registry ecosystem has a serious problem... and not just npm. People are aware of this but maybe this will make them a bit more aware

    2022 · github.com

  8. 8UA
  9. 9IO
  10. 10AU

    A lot of vendors and open-source projects shared guidance on protecting users from downloading malicious NPM packages after the Shai-Hulud campaign — but almost nothing focused on protecting maintainers from accidentally (or maliciously) publishing them. So we built a small tool that continuously monitors your NPM packages and automatically unpublishes any version not produced by your CI workflow.

    Nov 2025 · github.com

  11. 11

    Visualize your AI supply chain as an interactive map

    Mar 2026 · github.com

  12. 12NA
  13. 13NA

    2025 · github.com

  14. 14

    AI-native package manager for JavaScript, powered by MCP

    2025

  15. 15PS
  16. 16AA
  17. 17IB

    Hi HN, I built a tool [1] that resolves breaking changes when you upgrade npm packages. I know keeping my dependencies updated is good hygiene but I really have no motivations to do them. The time to fix breaking changes then validate them makes the ROI lopsided. Automating these helps me reduce the barrier to a good habit. It works on typescript and tsx projects. BYOK (bring your own GPT-4 key) for the codegen. MIT license. How does it work? - Bumps the package version, builds your project, and then runs tsc over your project to understand what breaks - Uses ts-morph [2] to create an AST of…

    2024 · github.com

  18. 18NT
  19. 19AA

    We've rolled out a feature for openbase.com that we think is a DX game changer for Node devs. Since the emergence of ECMA Script modules, it's been a continuous guessing game as to what kind of exports a package has. That's never really been discoverable without using a site like unpkg, or installing the package and inspecting package.json. Openbase now displays the ES Module support level (e.g. type of exports) on all of their package pages. We added this feature because our devs are some of the folks continually caught off guard by installing an NPM dependency only to find out it's…

    2022

  20. 20GA
  21. 21TN

    Dec 2025 · tpmjs.com

  22. 22NA
  23. 23NF
  24. 24PA

Ranked by how close each launch is in meaning, then by votes. Refine with a description →