Overview
Features
Next-gen Software Composition Analysis
Vulnerability and malicious package detection, focusing on real code usage rather than noisy dependency lists.
Malicious Package Detection
Real-time protection against malicious packages via SafeDep Cloud, with a fallback to Query Mode when an API key is not provided.
Policy as Code
Define security policies using CEL expressions to enforce context-specific security requirements.
Multi-Format / Multi-Ecosystem Support
Supports npm, PyPI, Maven, Go, Ruby, Rust, PHP, Docker/OCI, SBOMs (CycloneDX, SPDX), binary artifacts, and direct source code scanning.
CI/CD Native
Built for DevSecOps workflows with integrations for GitHub Actions, GitLab CI, and more.
MCP Server
Vet open source packages from AI-suggested code via an MCP server using SSE transport (start with vet server mcp --server-type sse).
Agents
Run AI agents to query and analyze scan results.
Who Is This For?
- Developers:Vet AI-suggested code packages in MCP workflows to ensure safer software.
- Security engineers:Define and enforce security policies against AI-proposed packages within MCP workflows.




