pkgsign is a CLI tool for signing and verifying npm and yarn packages. It allows for signing packages with PGP private keys or keybase.io for simplicity. Recently, several packages went missing from the npm registry, highlighting the importance of package signing to prevent unauthorized modifications and ensure trust in package sources.
Common questions about pkgsign including features, pricing, alternatives, and user reviews.
pkgsign is A CLI tool for signing and verifying npm and yarn packages. It is a Application Security solution designed to help security teams with NPM, Package Security, Supply Chain Security.
pkgsign is a free Application Security tool. This makes it accessible for organizations of all sizes, from startups to enterprises. Visit https://github.com/RedpointGames/pkgsign/ for download and installation instructions.
Popular alternatives to pkgsign include:
Compare these tools and more at https://cybersectools.com/categories/application-security
pkgsign is for security teams and organizations that need NPM, Package Security, Supply Chain Security. It's particularly suitable for small to medium-sized teams looking for cost-effective solutions. Other Application Security tools can be found at https://cybersectools.com/categories/application-security
Software supply chain security platform detecting malware in dependencies
Malware-resistant software libraries rebuilt from source for multiple languages
npm-zoo is a curated database of known malicious NPM packages that helps developers and security researchers identify and avoid potentially harmful dependencies in their projects.
Software supply chain security platform with SCA, package firewall & threat intel