What problem does it solve?
Identify unsafe, unmaintained, or legally incompatible third-party packages before adoption and persist findings into the project knowledge graph so future sessions recall risks and decisions.
Core Features & Use Cases
- Health Audit: Check recent downloads, last release, maintainer activity, and OpenSSF Scorecard to judge maintenance and adoption.
- Vulnerability & Transitive Analysis: Run ecosystem audits, count and evaluate transitive dependencies, and surface unpatched CVEs.
- License Compatibility: Verify license chains and flag copyleft or ambiguous licenses that could contaminate the project.
- Supply Chain Signals: Detect typosquatting, suspicious release bursts, install-script risks, and binary artifacts.
- Graph Integration: Produce clear ADOPT/CAUTION/REJECT recommendations and persist Dependency and SecurityConcern nodes to SeleneDB for cross-session tracking.
Quick Start
Audit the dependency [email protected] and provide a concise ADOPT/CAUTION/REJECT recommendation with findings and any SecurityConcern nodes written to the project's SeleneDB graph.