What problem does it solve?
External recon for software supply-chain surfaces to surface vulnerability patterns such as dependency confusion, package typosquats, GitHub Actions workflow injections, and exposed container registries. It helps identify SBOM leakage, internal-package-name leakage, and CI/CD exposure in targets with public artifacts.
Core Features & Use Cases
- Dependency-confusion detection across npm/PyPI/go modules and registries.
- Typosquat candidate discovery and mapping to potential uptake points.
- GitHub Actions workflow review for potential injection points and secret exposure.
- SBOM mining to enumerate transitive dependencies and known CVEs.
- Registry exposure discovery in Docker/OCI registries and artifact feeds.
- CI/CD configuration exposure discovery and governance improvements.
- Use case: OSINT on a public GitHub org to assess external risk and prioritize remediation across supply chains.
Quick Start
Analyze a target's public GitHub org and registries to surface dep-confusion and workflow risks.