# safedep/vet

Protect against malicious open source packages 🤖

Repository: https://github.com/safedep/vet
Canonical: https://ross.abutalabs.com/products/safedep-vet
Homepage: https://safedep.io
Language: Go
License: Apache-2.0
License Family: permissive
Topics: devsecops, security, supply-chain-security, policy-as-code, software-composition-analysis, golang, npm, pypi, rubygems, static-analysis, hacktoberfest
Last push: 2026-08-25T10:00:14+00:00

## Health v2 (maintenance only)
Score: 93/100 (v2, computed 2026-09-03T02:39:23.370411+00:00)
- activity 99, release rhythm 85, longevity 95
- inputs: {"age_days": 1342, "days_push": 8, "days_rel": 20, "gap_med": 7, "n_releases_24m": 70}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1103, forks 111 (observed 2026-08-28T04:03:36.169962+00:00)

## What it is
vet is an open-source CLI tool for software composition analysis that scans open-source dependencies for malicious packages and vulnerabilities, and enforces policy-as-code using CEL expressions. It integrates into CI/CD pipelines as a zero-config security guardrail and supports ecosystems like npm, PyPI, and RubyGems.

## Use cases
- scan npm and pypi dependencies for malicious packages before shipping
- enforce license and vulnerability policy as code in CI
- generate an SBOM for my repository
- block risky open source packages in pull requests
- cut down CVE noise by checking actual code usage of dependencies
- audit dependencies for supply chain attacks like Shai-Hulud

## When to choose
- you want a free, open-source SCA tool with policy-as-code enforcement in CI/CD
- you need malicious package detection across npm, PyPI, and RubyGems ecosystems
- you want SBOM generation and dependency scanning from a single CLI

## When to avoid
- you need dynamic behavioral malware analysis without a SafeDep Cloud account
- you require org-wide dashboards and centralized policy management, which are paid SaaS features

## Facets
- artifact type: cli-tool
- maturity: active
- function: security, vulnerability-scanning, dependency-audit, developer-tools, ci-cd
- domain: security, developer-tools
- platform: windows, cli
- tags: sca, sbom, policy-as-code, malicious-package-detection, software-supply-chain, cel, devops, supply-chain-security, linux, macos, docker, nodejs

## Member repositories
- safedep/vet (main) score 93

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:03:36.169962+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T06:45:34.512859+00:00, confidence not recorded.
  - readme: https://github.com/safedep/vet (fetched 2026-08-28T04:03:36.169962+00:00, sha 1729c2f04898)
  - homepage: https://safedep.io (fetched 2026-08-29T12:48:26.880840+00:00, sha 95b76763f5f3)
  - site_page: https://docs.safedep.io/ (fetched 2026-08-29T12:48:26.887307+00:00, sha 6b2b88eecdc9)
  - site_page: https://docs.safedep.io (fetched 2026-08-29T12:48:26.893724+00:00, sha 6b2b88eecdc9)
  - site_page: https://safedep.io/about (fetched 2026-08-29T12:48:26.896989+00:00, sha c8ac05dbd6b0)
  - site_page: https://safedep.io/developer-security (fetched 2026-08-29T12:48:26.883599+00:00, sha 1ddf550e6a06)
  - site_page: https://safedep.io/pricing (fetched 2026-08-29T12:48:26.885358+00:00, sha eab7c57096c1)
  - site_page: https://safedep.io/malicious-litellm-1-82-8-analysis (fetched 2026-08-29T12:48:26.888948+00:00, sha 4d44e8846df6)
  - site_page: https://safedep.io/youtube-ad-fake-tradingview-macos-stealer (fetched 2026-08-29T12:48:26.891367+00:00, sha ae7361afad35)
  - site_page: https://safedep.io/faq (fetched 2026-08-29T12:48:26.895313+00:00, sha 2792d62596a8)
- Data as of 2026-08-30T08:39:29.467469+00:00.
