For platform & security teams
Catch malicious packages before the advisory exists.
PkgRadar statically scans every new release across nine ecosystems and gates it in your CI — blocking a compromised dependency before it's ever installed. Typically hours to days before the public OSV advisory exists.
Flagged-first receipts →Audited accuracyvs Socket & Snyk
Free instant verdict, no signup — see static findings and any campaign link for a scanned release. Want it on every PR? Start free — 25 scans/mo.
Drop it into your pipeline
Block malicious dependencies in the pull request — one step.
The composite GitHub Action scans every changed dependency and fails the check before a compromised package merges. Auto-detects npm, PyPI, Cargo and more lockfiles. CLI, fail-on threshold & self-host options →
# .github/workflows/pkgradar.yml — gate every PR
- uses: PkgRadar/pkgradar-cli@v1
env:
PKGRADAR_TOKEN: ${{ secrets.PKGRADAR_TOKEN }}Coverage by ecosystem
The same gate, nine registries. Per-ecosystem detail →
Candidate cluster queue
0High-signal release queue
0No high-signal releases stored yet.
Detection model
From registry update to build decision
API verdict
Review{
"package": "package@version",
"verdict": "review",
"score": 42,
"mode": "static",
"decision": "review"
}curl -X POST /gate/npm -H 'Authorization: Bearer $PKGRADAR_TOKEN'Real attacks
Built to catch the supply-chain attacks teams actually face.
Shai-Hulud worm. tj-actions/changed-files takeover. ua-parser-js postinstall miner. event-stream / flatmap-stream. colors.js + faker.js sabotage. polyfill.io takeover. @solana/web3.js key exfiltration. We map each one to the static indicators PkgRadar already hunts.
Audit-ready evidence
Evidence that maps to SOC 2, NIST SSDF, ISO 27001 & the EU CRA.
Every static finding, gate decision, and campaign record is an artifact your auditor can sample. The /trust page enumerates the exact controls PkgRadar evidences — CC7 monitoring, CC8 change management, NIST SSDF PW.4 dependency verification, ISO 27001 A.5.21 supply chain, and EU CRA due-diligence obligations.
- SOC 2CC7 monitoring · CC8 change mgmt · CC9 vendor risk
- NIST SSDF v1.1PW.4 dependency review · PW.7 analysis · RV.1
- ISO 27001:2022A.5.21 supply chain · A.8.28 secure coding
- EU CRAAnnex I §1+§2 · Article 13 due diligence