# SafePack

Know what's in your code - and what's risky.

Every open-source package in your GitHub repos. Vulnerabilities ranked by real exploit risk. Malware and license violations flagged.

Runs on-prem. Request access: hello@safepack.dev - Book a demo: https://cal.com/safepack/30min

## Supported ecosystems

npm, PyPI, Maven, Go, GitHub Actions and more.

## Where risk enters

Most of the code you ship is code you didn't write.

- Repositories (available now)
- Developers and AI agents (coming soon)
- Pull requests (coming soon)
- CI pipelines (coming soon)

SafePack checks every package and ranks findings by exploit risk, with Slack alerts.

## One place for every dependency

Dependency Visibility: every package in every repo, riskiest first. Views for vulnerabilities, malware, dependencies and AI BOM.

Coming soon:

- Supply Chain Firewall: blocks risky packages at install time on laptops, AI agents and CI.
- PR Review: security review of every pull request.

## How it works

1. Deploy on-prem: runs on your own servers or private cloud.
2. Connect GitHub: choose the repositories to monitor.
3. Fix what matters first: the riskiest issues come first, with Slack alerts.

## Common questions

**Is SafePack a SaaS product?**
No. SafePack runs on-prem, in your own infrastructure.

**Where does the risk data come from?**
From [OSV.dev](https://osv.dev), the open database of vulnerabilities and malicious packages. Exploit risk comes from [FIRST EPSS](https://www.first.org/epss/), and anything on the [CISA KEV](https://www.cisa.gov/known-exploited-vulnerabilities-catalog) list of actively exploited vulnerabilities shows as 100% exploit risk.

**What data leaves our infrastructure?**
Your source code is never copied. Only package names and versions are checked against public databases. Findings stay in your own database and any Slack channel you connect.

**What access does SafePack need to GitHub?**
Read access to the repositories you choose.

**Which ecosystems are supported?**
npm, PyPI, Maven, Go, GitHub Actions and more.

## Contact

hello@safepack.dev - [About](https://safepack.dev/about.md) - [Contact](https://safepack.dev/contact.md) - [Privacy](https://safepack.dev/privacy.md)
