SafeDep
@safedepio
Followers
115
Following
233
Media
98
Statuses
222
Open Source Software Supply Chain Security | Built for devs | Built in public | https://t.co/QictxtHdL6
Joined March 2023
From Code to Server, we’ve got you covered! Integrate SafeDep at every stage of your SDLC and stay protected from malicious open-source software.
0
1
4
⚠️ Open Source Software Supply Chain attack targeting Hyatt internal dependencies through dependency confusion attack. Read more ➡️ https://t.co/Ss2nz5H0ZX
safedep.io
Three malicious npm packages disguised as Hyatt internal dependencies were discovered using install hooks to execute malicious payloads. All packages share identical attack patterns and infrastruct...
0
4
5
This Diwali light diyas, not vulnerabilities.🪔 vet ensures your supply chain shines bright and minus the fire hazards.😎 #Diwali #SecureCoding #SafeDep
0
0
5
When you have the SafeDep GitHub App installed, you can just sit back, relax, and focus on building. 👉 https://t.co/VUbAaMSIhI
1
0
8
Heading to Bengaluru tomorrow! I’ll be speaking at @OWASP AppSec Days about our Dynamic Malware Analyzer: https://t.co/tHL2prqVm6 Exciting times ahead 😁
safedep.io
Exploring the idea of building a complementary system that can verify and correlate static analysis findings. Thats where dynamic analysis comes in ie. the ability to "run" an open source package in...
4
1
8
Along with the new release packed with major improvements, Vet has also crossed 800+ GitHub stars🎉 A huge thanks to everyone contributing to securing open source software supply chains💙
New version of vet released with multiple bug fixes and feature updates. ➡️ Policy language revamp ➡️ Multiple bug fixes ➡️ Console experience improvements Everything you need to audit, analyse and secure your open source software supply chain. https://t.co/SZavyaJRsO
0
0
4
In security, sometimes we overlap quantitative and qualitative solution. This is a mistake. Even with AI, it will be nearly impossible for a static code analysis tool to beat a security researcher like duke or taviso on novelty (quality). But it can beat them on quantity.
1
1
3
Wondering where and how to contribute in SafeDep projects this #Hacktoberfest2025 . Well, no need to wonder anymore. Here is a quick guide to help you with the projects you can start contribute to https://t.co/E3nvsjY4Ur
#OpenSource #vet
0
0
4
Every part of our rebranding reflects how we think about security. It’s not about fear, it’s about integrity. It’s not about control, it’s about trust. And new SafeDep is all about it. So its not about to shouting “security” but simply feeling secure.
We got a chance to give @safedepio a new home — and reimagine what trust looks like in a developer-first world. Also special because @virajux , @chetna_ranaa , and I the OG crew behind Olvy’s brand, GTM, and product design teamed up again to build the next generation of design
0
1
6
Inspired by Gitlab's libbehave, I spent my weekend adding Go callgraph generation support to our xbom tool. It uses static code analysis to build a callgraph with simple DFA with assignment tracking and type propagation. Eventually will be in vet. https://t.co/SZavyaJjDg
0
1
2
Shoutout to @safedepio for the rapid response and coordinated disclosure. Read the full report & mitigation guidance: https://t.co/c1Mu8SIlKo
mcpsec.dev
SafeDep Vet MCP Server is vulnerable to DNS rebinding attacks allowing malicious websites to bypass Same-Origin Policy and exfiltrate scan database contents through unauthorized MCP tool invocations.
0
1
3
Our blog just got a fresh new look!✨ If you like reading about real supply chain incidents, npm compromises, and how to stay ahead and safe - check it out👇 https://t.co/QGJ3TFKQS0
1
1
5
It's easy to get started with SafeDep, and with it, even easier to protect your code from malicious packages.
0
1
5
🚀 Hacktoberfest is HERE and we're ready! Join us in making vet even more awesome! Whether you're a first-timer or a seasoned pro, we'd LOVE your contributions! 💜 Let's build something amazing together! ✨ https://t.co/7TBhBhQVjS
1
3
6
You’re a one-person team with 10+ repos. You can’t manually audit every npm package. SafeDep GitHub App: ⚡ Zero config 👀 Scans PRs + deps in real-time 🛡️ Blocks malicious packages Spend time building your product, not chasing malware. 👉 https://t.co/VUbAaMTg7g
0
0
5
The policy experience revamp in vet is coming up well. We will have a much more capable policy language, expressed in CEL with rich data source to evaluate for policy decisions.
0
1
2