Show HN: DepsGuard – one command to harden NPM/pnpm/yarn/bun/uv configs
DepsGuard is a new open-source tool designed to harden configuration files for package managers like npm, pnpm, and yarn against supply chain attacks. It provides an interactive interface to review and apply security-focused settings without running package installs.
Why it matters
As supply chain attacks become more frequent, automated tools that simplify security hardening for developers are increasingly critical for software integrity.
_ _ __| | ___ _ __ ___ __ _ _ _ __ _ _ __ __| | / _` |/ _ \ '_ \/ __|/ _` | | | |/ _` | '__/ _` | | (_| | __/ |_) \__ \ (_| | |_| | (_| | | | (_| | \__,_|\___| .__/|___/\__, |\__,_|\__,_|_| \__,_| |_| |___/ Guard your dependencies against supply chain attacks. Single static binary, zero Rust crate dependencies.
The content is a technical description of a software tool and its features.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in