npq is a tool that safely installs packages with npm/yarn by auditing them as part of your install process. It performs sanity checks to ensure the package is safe to install, including: * Consulting the Snyk.io database of publicly disclosed vulnerabilities * Checking package age on npm * Verifying package download count as a popularity metric * Ensuring the package has a README file * Verifying the package has a LICENSE file * Checking for pre/post install scripts Once installed, npq can be used to safely install packages, such as `npq install express`.
Common questions about npq including features, pricing, alternatives, and user reviews.
npq is A tool that safely installs packages with npm/yarn by auditing them as part of your install process. It is a Application Security solution designed to help security teams with NPM, Supply Chain Security.
npq is a free Application Security tool. This makes it accessible for organizations of all sizes, from startups to enterprises. Visit https://github.com/lirantal/npq/ for download and installation instructions.
Popular alternatives to npq include:
Compare these tools and more at https://cybersectools.com/categories/application-security
npq is for security teams and organizations that need NPM, Supply Chain Security. It's particularly suitable for small to medium-sized teams looking for cost-effective solutions. Other Application Security tools can be found at https://cybersectools.com/categories/application-security
Software supply chain security platform detecting malware in dependencies
Malware-resistant software libraries rebuilt from source for multiple languages