pkgsign Logo

pkgsign

A CLI tool for signing and verifying npm and yarn packages.

95
Visit website
Compare
Compare
0
MCPThe entire cybersecurity market, one prompt awayTry MCP Access

pkgsign Description

pkgsign is a CLI tool for signing and verifying npm and yarn packages. It allows for signing packages with PGP private keys or keybase.io for simplicity. Recently, several packages went missing from the npm registry, highlighting the importance of package signing to prevent unauthorized modifications and ensure trust in package sources.

pkgsign FAQ

Common questions about pkgsign including features, pricing, alternatives, and user reviews.

pkgsign is A CLI tool for signing and verifying npm and yarn packages.. It is a Application Security solution designed to help security teams with NPM, Package Security, Supply Chain Security.

Have more questions? Browse our categories or search for specific tools.

ALTERNATIVES

Aikido Software Supply Chain Security Logo

Software supply chain security platform detecting malware in dependencies

0
Chainguard Libraries Logo

Malware-resistant software libraries rebuilt from source for multiple languages

0
Socket Logo

Detects and blocks malicious/vulnerable open source packages in supply chains.

0
Veracode Secure Your Software Supply Chain Logo

Software supply chain security platform with SCA, package firewall & threat intel

0
Checkmarx One Malicious Package Protection Logo

Detects malicious open-source packages across SDLC using 410K+ package database

0

Stay Updated with Mandos Brief

Get strategic cybersecurity insights in your inbox