{"_id":"@anwarblockchain/repo-shield","_rev":"2-f8554ab13f1af155e2c3a92659202db4","name":"@anwarblockchain/repo-shield","dist-tags":{"latest":"0.1.1"},"versions":{"0.1.0":{"name":"@anwarblockchain/repo-shield","version":"0.1.0","keywords":["security","malware","supply-chain","npm","hardhat","static-analysis"],"license":"MIT","_id":"@anwarblockchain/repo-shield@0.1.0","maintainers":[{"name":"anwarblockchain","email":"anwar.pluton@gmail.com"}],"homepage":"https://github.com/AnwarBlockChain/repo-shield#readme","bugs":{"url":"https://github.com/AnwarBlockChain/repo-shield/issues"},"bin":{"repo-shield":"dist/src/cli/index.js"},"dist":{"shasum":"bbf8d98d6896f4bf30a42b397152d62c2cf5b8f8","tarball":"https://registry.npmjs.org/@anwarblockchain/repo-shield/-/repo-shield-0.1.0.tgz","fileCount":168,"integrity":"sha512-5Cxo0uoU/xzb1fd5er5v/kM3OFxetxPhgWq4DawIdkcYbbHOwH0GWJKhCQvWr4FyOr1ZwMh3kIE6BeAKllGcGQ==","signatures":[{"sig":"MEYCIQDX6WHL/5X5P447mmkPXU/KvBXuOVQl/nDMIR56l6UpAAIhAO1IFa0kqO7pI2qUBH07X+0i4ThuP4wgvkg//iKaqRuB","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":276314},"main":"./dist/src/index.js","type":"module","types":"./dist/src/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/src/index.d.ts","import":"./dist/src/index.js"}},"gitHead":"0bcda3e014c9011cf87fd0883e35a16fee70b1b5","scripts":{"lint":"tsc -p tsconfig.json --noEmit","test":"npm run build && node --test dist/tests/**/*.test.js","build":"tsc -p tsconfig.json","prepare":"npm run build","test:ci":"npm run typecheck && npm run test","typecheck":"tsc -p tsconfig.json --noEmit"},"_npmUser":{"name":"anwarblockchain","email":"anwar.pluton@gmail.com"},"repository":{"url":"git+https://github.com/AnwarBlockChain/repo-shield.git","type":"git"},"_npmVersion":"11.17.0","description":"Static malware and supply-chain scanner for Node.js ecosystem repositories.","directories":{},"_nodeVersion":"24.19.0","dependencies":{"@babel/types":"^7.25.9","@babel/parser":"^7.25.9","@babel/traverse":"^7.25.9"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.6.3","@types/node":"^22.7.5","@types/babel__traverse":"^7.20.6"},"_npmOperationalInternal":{"tmp":"tmp/repo-shield_0.1.0_1787298096608_0.24538616421538673","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@anwarblockchain/repo-shield","version":"0.1.1","description":"Static malware and supply-chain scanner for Node.js ecosystem repositories.","type":"module","homepage":"https://github.com/AnwarBlockChain/repo-shield#readme","repository":{"type":"git","url":"git+https://github.com/AnwarBlockChain/repo-shield.git"},"bugs":{"url":"https://github.com/AnwarBlockChain/repo-shield/issues"},"main":"./dist/src/index.js","types":"./dist/src/index.d.ts","bin":{"repo-shield":"dist/src/cli/index.js"},"exports":{".":{"types":"./dist/src/index.d.ts","import":"./dist/src/index.js"}},"scripts":{"build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","lint":"tsc -p tsconfig.json --noEmit","test":"npm run build && node --test dist/tests/**/*.test.js","test:ci":"npm run typecheck && npm run test","prepare":"npm run build"},"keywords":["security","malware","supply-chain","npm","hardhat","static-analysis"],"license":"MIT","engines":{"node":">=20"},"publishConfig":{"access":"public"},"dependencies":{"@babel/parser":"^7.25.9","@babel/traverse":"^7.25.9","@babel/types":"^7.25.9"},"devDependencies":{"@types/babel__traverse":"^7.20.6","@types/node":"^22.7.5","typescript":"^5.6.3"},"gitHead":"58d5e55c6287ae06f056def17eac07985695849e","_id":"@anwarblockchain/repo-shield@0.1.1","_nodeVersion":"24.19.0","_npmVersion":"11.17.0","dist":{"integrity":"sha512-v0Z+zojhsy37P1xkDnWtHa7/luUsC58jNazIdQH2cvevYOd1o0lkZeRt9YSE2uEekRgBSPriqVIg2bAg9ffDJA==","shasum":"2eef49c2838e5bdd93bdba4363d28f151cdf5ac8","tarball":"https://registry.npmjs.org/@anwarblockchain/repo-shield/-/repo-shield-0.1.1.tgz","fileCount":168,"unpackedSize":281446,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIBH7Jm1z9EBYTdwQf5u3Sxn7GRGbCcmuuxTCi5bbeji2AiA+tl8BrlYoaHmaXYZ5oRR3gOk09lJrygurIODdUXdJ+g=="}]},"_npmUser":{"name":"anwarblockchain","email":"anwar.pluton@gmail.com"},"directories":{},"maintainers":[{"name":"anwarblockchain","email":"anwar.pluton@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/repo-shield_0.1.1_1787300581962_0.7452151485284346"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-21T07:41:36.469Z","modified":"2026-08-21T08:23:02.229Z","0.1.0":"2026-08-21T07:41:36.752Z","0.1.1":"2026-08-21T08:23:02.102Z"},"bugs":{"url":"https://github.com/AnwarBlockChain/repo-shield/issues"},"license":"MIT","homepage":"https://github.com/AnwarBlockChain/repo-shield#readme","keywords":["security","malware","supply-chain","npm","hardhat","static-analysis"],"repository":{"type":"git","url":"git+https://github.com/AnwarBlockChain/repo-shield.git"},"description":"Static malware and supply-chain scanner for Node.js ecosystem repositories.","maintainers":[{"name":"anwarblockchain","email":"anwar.pluton@gmail.com"}],"readme":"# repo-shield\n\n`repo-shield` is a static, offline-first malware and supply-chain scanner for repositories that participate in the Node.js ecosystem. It is designed to inspect hostile repository content without executing it.\n\n## Install\n\nGlobal CLI:\n\n```sh\nnpm install -g @anwarblockchain/repo-shield\n```\n\nProject-local CLI:\n\n```sh\nnpm install --save-dev @anwarblockchain/repo-shield\nnpx repo-shield scan .\n```\n\n## CLI Usage\n\n```sh\nrepo-shield scan .\nrepo-shield scan . --deep\nrepo-shield scan . --ci\nrepo-shield scan . --format json\nrepo-shield scan . --format sarif\nrepo-shield fix . --dry-run\nrepo-shield quarantine list\n```\n\nExit codes:\n\n```text\n0 = clean\n1 = low/medium suspicious findings\n2 = high/critical findings\n3 = scanner/internal failure\n```\n\nProgrammatic API:\n\n```ts\nimport { scanRepository, planRemediation, applyRemediation } from \"@anwarblockchain/repo-shield\";\n\nconst report = await scanRepository({\n  path: \"./project\",\n  mode: \"deep\"\n});\n\nconst plan = await planRemediation({ repositoryPath: \"./project\", report });\nawait applyRemediation({ repositoryPath: \"./project\", plan, apply: true });\n```\n\nNormal scans are read-only and offline. The scanner does not `require`, import, build, install, compile, execute scripts, execute Hardhat, call RPC endpoints, or run repository-controlled binaries.\n\n## Publish Checklist\n\nMaintainers should run this before publishing:\n\n```sh\nnpm run test:ci\nnpm pack --dry-run\nnpm publish --access public\n```\n","readmeFilename":"README.md"}