Skip to content
#

dependency-confusion

Here are 29 public repositories matching this topic...

oh supply chain my supply chain — a multi-ecosystem package malware scanner for PyPI, npm, crates.io, and Go. Static analysis plus a sandbox detonation engine, with pluggable detection content (open-core; AGPL engine, Apache-2.0 signatures).

  • Updated Jun 11, 2026
  • Python

Improve this page

Add a description, image, and links to the dependency-confusion topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the dependency-confusion topic, visit your repo's landing page and select "manage topics."

Learn more