Zero-dependency npm supply chain security tool. Catches ghost dependencies, scores install script behavior, and detects attacks before any advisory exists.
-
Updated
Apr 1, 2026 - TypeScript
Zero-dependency npm supply chain security tool. Catches ghost dependencies, scores install script behavior, and detects attacks before any advisory exists.
A Yarn plugin that diagnoses compatibility issues exposed by PnP and other strict Yarn environments, then explains and optionally remediates them with safe, explicit fixes.
Add a description, image, and links to the ghost-dependency topic page so that developers can more easily learn about it.
To associate your repository with the ghost-dependency topic, visit your repo's landing page and select "manage topics."