Alternatives
Products that do what pkg.vc does
Install npm packages from pull requests or branches
- 1

- 2DO
I kept seeing every npm/pnpm/yarn/bun/uv supply chain post end with the same advice (set a minimum release age, turn off install scripts), and while I know cooldowns are "controversial", they do work. But even if you convince people that they should set cooldowns, it seems many don't end up following through, not sure why, maybe because it means hand-editing five config files in five formats with five different time units, or perhaps the "it won't happen to me" syndrome (or "I'll do it later, it seems complicated" where it's actually very simple). So I created a tool that…
Jun 2026 · github.com
- 3
Block bad npm and pip packages. Before they download.
May 2026 · veln.sh
- 4NI
Our package registry ecosystem has a serious problem... and not just npm. People are aware of this but maybe this will make them a bit more aware
2022 · github.com
- 5SI
In light of the ongoing npm supply chain compromises, I built safe-install: https://www.npmjs.com/package/@gkiely/safe-install It brings a couple of protections I wanted from npm but are not built in. Similar to Bun’s trusted dependencies, it lets you disable install scripts by default and define a list of dependencies that are allowed to run build/install scripts: https://bun.com/docs/guides/install/trusted It also supports blocking exotic sub-dependencies, similar to pnpm’s `blockExoticSubdeps` setting:…
May 2026 · npmjs.com
- 6PN
pgxman is npm for Postgres extensions, simplifying the discovery and use of extensions so you can easily enhance your applications. Installing and updating Postgres extensions is an uphill battle. You're left searching for the right build tools and grappling with often unclear and incomplete compiling instructions to even try one out. But with pgxman, we've streamlined the process to one simple step: pgxman install [extension name]. For example, to build parquet_s3_fdw manually, you'd need to: 1. Download the parquet_s3_fdw source code; 2. Figure out how to build it by looking at README.…
2023 · pgxman.com
- 7
- 8OG
2017 · open-source.now.sh
- 9SN
This past quarter has been awash with sophisticated npm supply chain attacks like [Shai-Hulud](https://www.cisa.gov/news-events/alerts/2025/09/23/widesprea...() and the [Chalk/debug Compromise](https://www.wiz.io/blog/widespread-npm-supply-chain-attack-b...). This CLI helps protect users from recently compromised packages by only downloading packages that have been public for a while (default is 90 days or older). Install: npm install -g @dendronhq/safe-npm Usage: safe-npm install react@^18 lodash How it works: - Queries…
Nov 2025 · github.com
- 10

- 11RE
2020 · github.com
- 12PD
2021 · pickbetterpack.com
- 13PC
Code review conversations on GitHub can be frustratingly slow, now you can have them on Slack. Features: - Each pull request (PR) on GitHub creates a Slack channel (public or private) with all involved parties (creator, assignees, and reviewers). - An auto-generated summary in English of what the PR does, making it easier for reviewers to enter the context. - Notifications of workflow results, new commits, new approvals... are sent in the channel. - Code comments with context are available. The initial review still takes place on GitHub, but messages are then transferred to Slack for…
2023 · pullpo.io
- 14NP
Hey guys! I just released a NPM package to integrate a visual scripting editor into any node project (React, Vue, Angular... you name it). Basically, the goal is to provide your users a way to customize, automate, create new features for your product. Just like an open-source community, but without the barrier of code. Here's the homepage of the project: https://luna-park.app And a small tutorial for visual scripting: https://luna-park.app/challenge
2023 · npmjs.com
- 15WB
Hey HN, We’re two developers (co-founders) with a team of 20 who got tired of spending hours reviewing PRs, so we built Infinitcode.ai, an AI-powered code reviewer that: - *Summarizes PRs in plain English*: No more deciphering 1,000-line diff jungles - *Catches more than bugs*: Security holes, performance pitfalls, code smells, even typos (yes, we’ll flag “vurnerabilities” and vulnerabilities) - *Zero onboarding*: Works instantly—no “let me learn your codebase for weeks” nonsense. Why we’re posting: We’re in alpha and need brutal honesty. Roast our tool, mock our UI, or tell us why AI will…
2025 · infinitcode.ai
- 16

- 17GP
Hey HN, Every team I've been on has cobbled together some sort of combination of GitHub branch protections and custom scripts to make sure that PRs conform to organization policies and best practices. Things like: - When {X} file is changed, require review from team {Y} - When a new db migration is added, ensure that a special set of tests pass - Require multiple approvals when the PR is very large - Add a special label to PRs that include breaking changes - Allow emergencies / hotfixes to break glass and bypass all of the above Most teams tend to start out with a little script running…
2025 · gitguard.dev
- 18UA
2017 · unpkg.com
- 19PM
I learned Flask, Python, Uwsgi, and Nginx configuration in order to make this happen. Oh and if you're feeling generous, you can buy them for $2 a pop: https://prlibs.com/nocc
2012 · prlibs.com
- 20

- 21SP
Like many devs, we lived in Slack hell—random notifications, chaotic threads and PRs always getting missed! We tried everything: Slack bots, GitHub settings, follow-up msgs—nothing worked. So we built PullNotifier. PullNotifier ensures that every PR gets the attention it deserves. It makes sure the right people see them at the right time—without spamming everyone (so you don't have to send those awkward PR request msgs). What makes it different? One notification per PR: No more drowning in redundant messages. Smart routing: PRs go only to the relevant channels or reviewers. Instant…
2025 · pullnotifier.com
- 22

- 23SM
A simple .NET NuGet server implementation built on Node.js that provides essential NuGet v3 API endpoints. Key Features: * Easy setup, run NuGet server in 10 seconds! * NuGet V3 API compatibility: Support for modern NuGet client operations * No need database management: Store package file and nuspecs into filesystem directly, feel free any database managements * Package publish: Flexible client to upload .nupkg files via HTTP POST using cURL and others * Basic authentication: Setup authentication for publish and general access when you want it * Reverse proxy support: Configurable trusted…
2025 · github.com
- 24PS
2019 · pkgstats.com
Ranked by how close each launch is in meaning, then by votes. Refine with a description →