awesome-dependency-audit
Read-only supply-chain audit of packages and agent extensions: lockfiles, typosquats, dependency confusion, install scripts, licenses, CVEs. Use when asked if a package, manifest change or bot bump is safe.
- License
- MIT
Pinned to revision fd69948effbe, so it is the text this page describes rather than whatever the author pushed since.
Files
Every link opens the file at its source, pinned to the revision this page describes.