Dependency Combobulator
-
Updated
Jan 10, 2024 - Python
Dependency Combobulator
Dependency Confusion Security Testing Tool
DustiLock is a tool to find which of your dependencies is susceptible to a Dependency Confusion attack.
tool for checking potential dependency confusion
A tool to investigate Dependency Confusion in Artifactory
Detect potential typosquatting packages across package ecosystems
An OOB server for receiving callbacks from various security testing workflows, especially supply chain attacks.
## Auto-archived due to inactivity. ## Yorkshire is your friend, yorkshire checks Python's requirements files for a possible dependency confusion.
oh supply chain my supply chain — a multi-ecosystem package malware scanner for PyPI, npm, crates.io, and Go. Static analysis plus a sandbox detonation engine, with pluggable detection content (open-core; AGPL engine, Apache-2.0 signatures).
Python-based tool for identifying potential dependency confusion vulnerabilities in JavaScript (`package.json`) and Python (`requirements.txt`) projects
Chrome extension to detect dependency confusion vulnerabilities in GitHub repositories (NPM, PyPI, Ruby)
npm PoC packages
Static supply-chain checks for npm and PyPI packages, lockfiles, provenance, and known malware.
Supply-chain security tool that cross-references your private package inventory against public registries, flags dependency confusion risks, and explains why each collision matters
Simple bash dependency confusion checker (npm, python and ruby)
Demonstration of Dependency Confusion applied to .NET and NuGet
High-performance Go tool for detecting Dependency Confusion vulnerabilities by scanning JavaScript files and checking unclaimed packages on npm registry.
DependencyConfusion is tool used for finding any library used by the project that might be vulnerable to dependency confusion attack.
Project to handle requests from malicious PoC of Dependency Confusion or Similar Name packages. Also can be used to generate those packages (gem, npm, pip).
To associate your repository with the dependency-confusion topic, visit your repo's landing page and select "manage topics."