
PackageSentinel
A tool to help developers stay safe with npm dependencies.
What it does
🛡️ Introducing PackageSentinel — a tool built to help developers stay safe with their npm dependencies. 'npm audit' gives you a wall of terminal text. PackageSentinel gives you clarity. ✅ Quickly research any npm package before you install it ✅ Visual security scores instead of cryptic CLI output ✅ Click through the full dependency tree interactively ✅ Zero setup — just open a browser and search Built with React + TypeScript + Tailwind CSS, powered by the OSV.dev vulnerability database.
Does the same job
all alternatives →- SNSafe-NPM – only install packages that are +90 days oldNov 2025 · github.com · ▲90
This past quarter has been awash with sophisticated npm supply chain attacks like [Shai-Hulud](https://www.cisa.gov/news-events/alerts/2025/09/23/widesprea...() and the [Chalk/debug Compromise](https://www.wiz.io/blog/widespread-npm-supply-chain-attack-b...). This CLI helps protect users from recently compromised packages by only downloading packages that have been public for a while (default is 90 days or older). Install: npm install -g @dendronhq/safe-npm Usage: safe-npm install react@^18 lodash How it works: - Queries…

- IMI made a CLI tool to create web extensions with no build configuration2024 · github.com · ▲381
Hello HN! I'm the creator and solo developer of Extension.js, a development tool for browser extensions with built-in support for TypeScript, WebAssembly, React, and modern JavaScript. Developers use it to spend less time configuring the compilation config or learning new frameworks and more time actually writing code. Most projects similar to Extension.js rely on some sort of abstraction or configuration to get started, making the initial development process slow given the extra learning curve and setup guidelines. By using Extension.js, adding the package to your npm scripts is all it…
- SISafe-install – safer NPM installs with trusted build dependenciesMay 2026 · npmjs.com · ▲19
In light of the ongoing npm supply chain compromises, I built safe-install: https://www.npmjs.com/package/@gkiely/safe-install It brings a couple of protections I wanted from npm but are not built in. Similar to Bun’s trusted dependencies, it lets you disable install scripts by default and define a list of dependencies that are allowed to run build/install scripts: https://bun.com/docs/guides/install/trusted It also supports blocking exotic sub-dependencies, similar to pnpm’s `blockExoticSubdeps` setting:…
- NInpm install actual-malware2022 · github.com · ▲55
Our package registry ecosystem has a serious problem... and not just npm. People are aware of this but maybe this will make them a bit more aware
- TTTips to stay safe from NPM supply chain attacksSep 2025 · github.com · ▲96
Hi everyone, given the recent increase of attacks on the NPM supply chain, I've put together a list of tips and tricks to help developers stay secure on this specific topic: https://github.com/bodadotsh/npm-security-best-practices I'd love for you to check it out, and contribute your own insights and best practices to make this a comprehensive resource for the community. Cheers!
More dev tools this month
the category →



The first open-source price index for GPU compute
Dev tools · 10d ago · getcomputable.com

OpenTrailPaper is open-source bike computer firmware for the LilyGO T5S3 4.7" E-Paper PRO. It supports offline maps, GPX routes, FIT recording and Bluetooth sensors.
Dev tools · 2d ago · opentrailpaper.com

Open-source GTM skills for technical founders
Dev tools · 29d ago · gtmcofounder.com