Runs on-prem

Know what’s in your code - and what’s risky.

Every open-source package in your GitHub repos. Vulnerabilities ranked by real exploit risk. Malware and license violations flagged.

Supported ecosystems

  • npm
  • PyPI
  • Maven
  • Go
  • GitHub Actions
  • and more

Where risk enters

Most of the code you ship is code you didn’t write.

  • Repositories
  • Developers & AI agentsSoon
  • Pull requestsSoon
  • CI pipelinesSoon
  • npm
  • PyPI
  • Maven
  • Go
  • GitHub Actions
  • and more
SafePack
  • Ranked by risk
  • Slack alerts

One place for every dependency

Dependency Visibility

Every package in every repo, riskiest first.

PackageSeverityCVE/GHSA IDInstalled VersionFixed VersionEcosystemExploit Risk
org.apache.logging.log4j:log4j-coreCriticalCVE-2021-442282.14.12.15.0Maven100%
golang.org/x/netMediumCVE-2023-45288v0.17.0v0.23.0Go92%
lodashHighCVE-2021-233374.17.204.17.21npm21%
requestsMediumCVE-2024-470812.31.02.32.4PyPI1%
Package NameMalware IDEcosystemInstalled VersionFixed VersionAffected ReposPublished
react-nodejsMAL-2026-17294npm19.3.0No fix229-09-2026
spo365-graphMAL-2026-17421PyPI1.1.0No fix101-10-2026
github.com/BufferZoneCorp/log-coreMAL-2026-3628Gov0.1.0No fix113-05-2026
PackageEcosystemInstalled VersionLicense
example-pdf-renderMaven4.2.0GPL-3.0
actions/checkoutGitHub Actionsv4MIT
lodashnpm4.17.20MIT
requestsPyPI2.31.0Apache-2.0
ComponentCategoryProviderEcosystemInstalled VersionSeverityExploit Risk
example-llm-gatewayFrameworkExample AIPyPI2.1.0High64%
demo-agent-coreFrameworkDemo LabsPyPI0.3.7Critical43%
sample-mcp-serverFrameworkMCPnpm1.4.2Medium12%
demo-embeddingsLibraryDemo LabsPyPI5.2.0Low3%
Coming soon

Supply Chain Firewall

Blocks risky packages at install time on laptops, AI agents and CI.

Coming soon

PR Review

Security review of every pull request.

How it works

  1. Deploy on-prem

    Runs on your own servers or private cloud.

  2. Connect GitHub

    Choose the repositories to monitor.

  3. Fix what matters first

    The riskiest issues come first, with Slack alerts.

Common questions

Is SafePack a SaaS product?

No. SafePack runs on-prem, in your own infrastructure.

Where does the risk data come from?

From OSV.dev, the open database of vulnerabilities and malicious packages. Exploit risk comes from FIRST EPSS, and anything on the CISA KEV list of actively exploited vulnerabilities shows as 100% exploit risk.

What data leaves our infrastructure?

Your source code is never copied. Only package names and versions are checked against public databases. Findings stay in your own database and any Slack channel you connect.

What access does SafePack need to GitHub?

Read access to the repositories you choose.

Which ecosystems are supported?

npm, PyPI, Maven, Go, GitHub Actions and more.

See what’s in your code.