Build SAFE with Secure Open-Source Software
The Largest Resource of Comprehensive Risk Assessments on Open Source. Totally Free.
The Largest Resource of Comprehensive Risk Assessments on Open Source. Totally Free.
Attacks on public open-source repositories are now as pervasive as developers' use of open-source dependencies. Spectra Assure Community monitors over six million open-source packages to identify malware, code tampering, and indicators of software supply chain attacks. It provides a free risk assessment for open-source components from the most popular package repositories such as npm, NuGet, PyPi, and RubyGems, so you can be sure the open-source packages in your applications are free from malicious code and supply chain attacks.
ReversingLabs provides community insights from our team of dedicated threat researchers. From insight into malicious activity in the VSCode marketplace to compromised ultralytics PyPI packages, our mission is to keep the community forewarned and forearmed of novel supply chain attacks. Additionally, Spectra Assure helps with removing malicious code from package repositories, and we contribute to the Linux Foundations OSSF Malicious Packages Database.
Learn about complex binary analysis and how it tackles supply chain threats like malware, tampering, exposed secrets and more — all without source code.
Learn MoreThe package's history is a lesson in why tracking open source threats is such a challenge — and highlights the value of RL's new Spectra Assure Community.
Learn MoreGet in-depth insights into the latest software supply chain threat.
Learn More