nowfound

Alternatives

Products that do what Package Helper does

Scan and auto-fix GitHub vulnerabilities in seconds

  1. 1

    Fix vulnerabilities in Node & npm dependencies with a click.

    2016

  2. 2

    Your packages, at home with their code

    2019

  3. 3

    The ultimate search engine for GitHub repositories

    2024

  4. 4

    Make devs notice your repo

    Nov 2025

  5. 5GB
  6. 6

    Configure once, prevent the next compromised package install

    May 2026 · depsguard.com

  7. 7NI

    Our package registry ecosystem has a serious problem... and not just npm. People are aware of this but maybe this will make them a bit more aware

    2022 · github.com

  8. 8
    GitJin116

    GitHub repos, issues, and PRs in one clear dashboard

    Dec 2025

  9. 9CA

    Hello HN! I built a pre-commit code scanner that checks your staged changes for security vulnerabilities every time you run 'git commit'. I am an inexperienced programmer and this is my first personal project. Any feedback, positive or negative, big or small, relevant or not, would be greatly helpful and appreciated! The tool requires Gitleaks and Python to run, you will also need to use your own AI API key, which I understand is a big setup friction. You can check out my demo video instead if that is more convenient: https://youtu.be/ZYe5vWFRTus?si=9Fv8DhTHktwDK4mV Thank you…

    Jun 2026 · github.com

  10. 10IB
  11. 11PS

    Hey HN, it's Farrukh and Umar. We're building listen.dev–a tool for proactive security monitoring in GitHub Actions to secure software releases from supply chain threats. Why we built this: As friends and collaborators for over a decade, we've been working on various startup ideas in dev tools and infrastructure. In 2017, while building an ML ops toolkit on Kubernetes, we got hacked. During a pilot with a fintech customer, our cluster became victim to a crypto-jacking attack. As it turned out, a dependency in our container base image contained malware (a Monero miner) which triggered inside…

    2024

  12. 12

    Block bad npm and pip packages. Before they download.

    May 2026 · veln.sh

  13. 13

    AI code reviewer for GitHub PRs — catches bugs instantly

    Jun 2026 · buglens.app

  14. 14IB

    Linux Foundation survey says 70-90% of modern software constitute OSS code. Yet we are stuck with tools that scan only for vulnerabilities in 3rd party libraries and that too with high degree of false positives. I built `vet` for policy and data driven analysis of 3rd party packages that goes beyond only vulnerability and allows codifying organisational policies related to OSS consumption. https://github.com/safedep/vet Looking forward to feedback and suggestions from HN :)

    2023 · github.com

  15. 15
    trawld4

    catch vulnerable dependencies before they catch you

    May 2026 · trawld.vercel.app

  16. 16

    Security Scanner for AI-generated Code

    7d ago · scanity.dev

  17. 17TD

    Trusty - Search for an open source package to understand its trustworthiness based on activity, provenance, and more. Brought to you by the founders of projects such as Kubernetes and Sigstore. Hey, Luke here the CTO of stacklok. This is an early experimental preview of Trusty. We use statistical analysis to observe millions of packages and found that Malware typically follows certain patterns. We found this tool really useful to help understand the packages we our pulling into our software and wanted to share it with others. It's still early in and we have a lot more features that will be…

    2023 · trustypkg.dev

  18. 18GP

    Hey HN, Every team I've been on has cobbled together some sort of combination of GitHub branch protections and custom scripts to make sure that PRs conform to organization policies and best practices. Things like: - When {X} file is changed, require review from team {Y} - When a new db migration is added, ensure that a special set of tests pass - Require multiple approvals when the PR is very large - Add a special label to PRs that include breaking changes - Allow emergencies / hotfixes to break glass and bypass all of the above Most teams tend to start out with a little script running…

    2025 · gitguard.dev

  19. 19

    Paste a bug. Get a pull request.

    Jun 2026 · cearn.vercel.app

  20. 20AU

    A lot of vendors and open-source projects shared guidance on protecting users from downloading malicious NPM packages after the Shai-Hulud campaign — but almost nothing focused on protecting maintainers from accidentally (or maliciously) publishing them. So we built a small tool that continuously monitors your NPM packages and automatically unpublishes any version not produced by your CI workflow.

    Nov 2025 · github.com

  21. 21

    Scan your repo and get secure code in 1 click.

    May 2026 · prev-ent.com

  22. 22

    Your stack's AI engineer — Detects bugs and fixes them

    May 2026 · tracelit.io

  23. 23

    Top 10 fixes for your repo, not a 500-warning pile

    May 2026

  24. 24GC

Ranked by how close each launch is in meaning, then by votes. Refine with a description →