Supply Chain Check
Find malicious and vulnerable open-source packages in your npm, Composer and Python projects.
The Supply Chain Check reads the dependency files of your projects and tells you which packages are known-malicious or vulnerable, and what to upgrade to.
Supported files
| Ecosystem | Lockfiles (exact versions) | Manifests (version ranges) |
|---|---|---|
| npm / JavaScript | package-lock.json, yarn.lock, pnpm-lock.yaml |
package.json |
| Composer / PHP | composer.lock |
composer.json |
| Python | poetry.lock, uv.lock, Pipfile.lock, pinned requirements*.txt |
requirements*.txt |
Upload lockfiles whenever you can. With only a manifest the versions aren't exact. Malicious packages are still detected, but version-specific vulnerabilities can't be, and the result says coverage is partial. Files are limited to 5 MiB and 20,000 packages each.
How to run it
- Open Settings → Software and upload your files. Group a manifest with its lockfile under the same project name.
- Open Assessment Products → Supply Chain Check and select the files to check.
- Place the order. The check starts straight away; no authorisation is needed, because nothing of yours is scanned.
What you get
- One critical finding per malicious package, with instructions to remove it and rotate any secrets the package could have reached (CI, developer machines).
- One finding per vulnerable package (not one per CVE), with the lowest version that fixes every advisory.
- Risk signals: install scripts, packages from git or URLs instead of the registry, private packages that couldn't be checked, missing integrity hashes, manifests without a lockfile.
If the advisory lookup fails, you get an incomplete result, never a false "all clear".
Your code stays private
- Files are parsed as data and then discarded. Only the package list, the file name and its checksum are kept.
- Only public package names and versions are looked up, against OSV.dev and the OpenSSF malicious-packages feed.
- Packages from a private registry, git or a local path are never sent anywhere. Their names could be confidential.
After the check, keep the files in Software: Stack Watch goes on watching them every day.
Price
€149 standalone, €129 on Essentials. Included 1× per quarter on Managed and per month on vCISO.