Continuous Automation - Most developers forget to run npm audit until it's too late. SupplyGuard is an Invisible Shield that scans your project automatically on every file change.
Beyond the Database - Traditional scanners like npm audit are reactive—they only flag what's already reported. SupplyGuard is proactive, using a Zero-Day Radar to flag suspicious brand-new updates before they appear in any database.
🚀 Key Features
🚨 Zero-Day Supply-Chain Radar
Identifies packages published within the last 48 hours. This is a critical indicator of potential supply-chain attacks (like the recent axios malicious release).
🔍 Multi-Ecosystem OSV.dev Integration
Comprehensive security scanning using the OSV batch API for maximum performance.
Node.js - npm, pnpm, yarn, bun (package.json, package-lock.json, pnpm-lock.yaml, yarn.lock)