Supply-chain security gate - dependency manifest parsing, SBOM (CycloneDX/SPDX), offline advisory matching, policy gates, post-quantum scanning.
-
Updated
Sep 22, 2026 - Python
Supply-chain security gate - dependency manifest parsing, SBOM (CycloneDX/SPDX), offline advisory matching, policy gates, post-quantum scanning.
👻 Stop installing packages that don't exist. When AI hallucinates names like "flask-gpt-helper", attackers register them as malware. Phantom Guard detects slopsquatting attacks across PyPI, npm & crates.io before you install.
Multi-gate open source supply chain trust validation pipeline with zero-day CVE expedited lane
Long-Term Support (LTS) security fork of urllib3 with backported CVE fixes for Python 3.7 and 3.8.
Durable decisioning for open-source vulnerability response. Proves upstream model replacements flip 15–49% of decisions overnight and gates them. Bit-for-bit replayable, exactly-once, injection-proof by construction.
Reachability-aware CVE prioritizer: tells you which vulnerabilities are actually reachable from your code, and drafts the GitHub issue for the ones that matter.
Explain and prioritize Node.js dependency risks for small projects
BitMEX Testnet research bot with fail-closed reconciliation, risk gates, a private read-only dashboard, and dependency security auditing.
Vet the packages & repos your AI assistant recommended — before you install. Catches hallucinated/slopsquatted names, CVEs, malware, fake stars, and license traps in 25 languages. MCP server so the assistant checks itself. No API key.
Checks public GitHub repos' Python/JS dependency manifests against OSV.dev
Hands-on demo for the OSS Trust Framework — 6 scenarios including live CVE detection, IronWorm and Miasma behavioral pattern matching, and a full zero-day MFA quorum workflow. 131 passing tests · all offline.
To associate your repository with the dependency-security topic, visit your repo's landing page and select "manage topics."