Loading...
pkgsign is a CLI tool for signing and verifying npm and yarn packages. It allows for signing packages with PGP private keys or keybase.io for simplicity. Recently, several packages went missing from the npm registry, highlighting the importance of package signing to prevent unauthorized modifications and ensure trust in package sources.
Common questions about pkgsign including features, pricing, alternatives, and user reviews.
pkgsign is A CLI tool for signing and verifying npm and yarn packages.. It is a Application Security solution designed to help security teams with NPM, Package Security, Supply Chain Security.
Software supply chain security platform detecting malware in dependencies
Malware-resistant software libraries rebuilt from source for multiple languages
Get strategic cybersecurity insights in your inbox
Detects and blocks malicious/vulnerable open source packages in supply chains.
Software supply chain security platform with SCA, package firewall & threat intel
Detects malicious open-source packages across SDLC using 410K+ package database