nowfound

Dev tools · alternatives · 2026

24 alternatives to SafeDep Vet

Identify open source risks

Below are 24 products that do a similar job, ranked by how close each is in meaning and then by launch-day votes. SafeDep Vet launched in 2023; newer entries below may have overtaken it.

  1. 1VA
  2. 2IB

    Linux Foundation survey says 70-90% of modern software constitute OSS code. Yet we are stuck with tools that scan only for vulnerabilities in 3rd party libraries and that too with high degree of false positives. I built `vet` for policy and data driven analysis of 3rd party packages that goes beyond only vulnerability and allows codifying organisational policies related to OSS consumption. https://github.com/safedep/vet Looking forward to feedback and suggestions from HN :)

    2023 · github.com · its alternatives →

  3. 3
    Opengrep▲340

    The open source code security engine

    2025 · its alternatives →

  4. 4
    Warestack▲444

    Agentic guardrails for safe releases

    2025 · warestack.com · its alternatives →

  5. 5

    Open safety reasoning models with custom safety policies

    Oct 2025 · openai.com · its alternatives →

  6. 6
    Dev Utils▲529

    Open-source tools for devs who don’t like ads

    2024 · its alternatives →

  7. 7
    Koidex▲387

    Know if a package, extension, or AI model is actually safe

    Feb 2026 · dex.koi.security · its alternatives →

  8. 8

    Optimize your Open Source project with deep insights

    2023 · its alternatives →

  9. 9MS

    I noticed the growing security concerns around MCP (https://news.ycombinator.com/item?id=43600192) and built an open source tool that can detect several patterns of tool poisoning attacks, exfiltration channels and cross-origin manipulations. MCP-Shield scans your installed servers (Cursor, Claude Desktop, etc.) and shows what each tool is trying to do at the instruction level, beyond just the API surface. It catches hidden instructions that try to read sensitive files, shadow other tools' behavior, or exfiltrate data. Example of what it detects: - Hidden instructions…

    2025 · github.com · its alternatives →

  10. 10
    vet▲1

    The safety net for curl | bash

    2025 · getvet.sh · its alternatives →

  11. 11
    Keep▲108

    Alerting, by developers, for developers

    2023 · its alternatives →

  12. 12OS
  13. 13
    Vet▲120

    Keep your coding agents honest

    Mar 2026 · imbue.com · its alternatives →

  14. 14

    Identify spam signups & bad actors

    2017 · its alternatives →

  15. 15VN

    If you are worried about the recent Lazarus group software supply chain attack, you should consider having guard rails that is more than conventional SCA. `vet` detects the package (version) published in the report as malware. Try out vet, its free and open source: https://github.com/safedep/vet More details on the attack: https://www.nodejs-security.com/blog/north-korea-malware-on-...

    2023 · github.com · its alternatives →

  16. 16VP
  17. 17DO

    Distr is designed to help software engineers distribute and manage their applications or agents in customer-controlled or shared-responsibility environments. You only need a Docker Compose file or Helm chart—everything else for on-prem is handled by the platform. We’re are an open source dev tool company. Over the past couple of months, we’ve spoken with dozens of software companies to understand their challenges with on-prem deployments. We analyzed the internal tools they’ve built and the best practices from existing solutions, combining them into a prebuilt, Open Source solution that…

    2025 · github.com · its alternatives →

  18. 18IB
  19. 19SS

    Excited to share the project I've been working on for the past 7 months! We've seen nearly weekly attacks against the open source software supply chain. I saw the seeds of this trend start in the mid 2015s as an open source maintainer and I've watched it only get worse over the years. I finally decided to try to solve this problem. Socket is taking an entirely new approach to one of the hardest problems in security in a stagnant part of the industry that has historically been obsessed with just reporting on known vulnerabilities. Unlike other scanning tools, Socket actually analyzes the…

    2022 · socket.dev · its alternatives →

  20. 20OO

    Hey HN! We’re Max and Thibault building OpenStatus.dev an OpenSource synthetic monitoring platform with incident managements 1 min demo: https://twitter.com/mxkaske/status/1685666982786404352 We have just reached 2000 stars on GitHub https://github.com/openstatusHQ/openstatus We are really excited to hear your feedback/questions and connect further: our emails are [email protected] and [email protected]. Thank you!

    2023 · openstatus.dev · its alternatives →

  21. 21

    Define safety at runtime for text and images

    Aug 2026 · mistral.ai · its alternatives →

  22. 22

    Find vulnerabilities in open-source code.

    2016 · its alternatives →

  23. 23
    Arnica▲97

    Behavior based software supply chain security

    2022 · its alternatives →

  24. 24

    Secure your JavaScript supply chain – block malware packages

    2022 · its alternatives →

Also compare

Ranked by how close each launch is in meaning, then by votes. Prices were read from each product’s own site when checked and can change. Refine with your own description →