"DepsGuard looks for npm, pnpm, yarn, bun, uv, pip, poetry, and aube on your machine, reads their config files, compares them to recommended supply-chain settings, and can apply fixes interactively. "

https://github.com/arnica/depsguard

#arch #archlinux #malware #supplychainattack #depsguard

GitHub - arnica/depsguard: Harden your package manager configs against supply chain attacks.

Harden your package manager configs against supply chain attacks. - arnica/depsguard

GitHub