{"_id":"supply-chain-guard","_rev":"168-1b4f46e5bce0b6585194feeee7640ff1","name":"supply-chain-guard","dist-tags":{"latest":"6.3.0"},"versions":{"1.0.0":{"name":"supply-chain-guard","version":"1.0.0","keywords":["security","supply-chain","malware-detection","npm","glassworm","scanner","cli","github-action"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@1.0.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"07a6ad4f8ef4145d5f047ed5124f2618eb65f607","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-1.0.0.tgz","fileCount":36,"integrity":"sha512-6EYq2yA08thizjbTE/KxmNlTJKQdEdukZN7U1N88vB+qFZS0i6+D4ScrAqyHyAkYeSDBEqj0IzTTXvIjzbsicg==","signatures":[{"sig":"MEQCIFWzyrIs+N3u2UMn+GBQIbWzFnLXkcsMkMiJ8iSQL73oAiAjplLCTW411KaQZ+Fd9/rQRyfuM0Psj4TvrBNPsd0ppg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":147169},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"26789f1ea73c15440995759de0f05fa95b299852","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"elvatis_com","email":"emre.kohler@elvatis.com"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"10.9.4","description":"Open-source supply-chain security scanner for npm, PyPI, and VS Code extensions. Detects GlassWorm and similar malware campaigns.","directories":{},"_nodeVersion":"22.22.1","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_1.0.0_1773892141671_0.9553451607712022","host":"s3://npm-registry-packages-npm-production"}},"2.0.0":{"name":"supply-chain-guard","version":"2.0.0","keywords":["security","supply-chain","malware-detection","npm","glassworm","scanner","cli","github-action"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@2.0.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"a4e65d896e7b6e1863479ea70f9836e60be31e26","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-2.0.0.tgz","fileCount":52,"integrity":"sha512-hgMnvSy2zUd1/9FLRsJTSoIV+HVGRtrQBjhszX6UGnud3QtySjFI9d+w59prarDti50w0ap4Fxx3pP65pFGKFg==","signatures":[{"sig":"MEUCIQDPBN9y0zYaxgmdh0w8oOI25LBt0x/eakX9fKUnGZsdpgIgJTQl+Mso2HqCIm+uhJIixxBMm1+fytcRRBhXfB0IrX4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":329100},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"89585992705572bd04046281c35e571340bcc33c","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"elvatis_com","email":"emre.kohler@elvatis.com"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"10.9.4","description":"Open-source supply-chain security scanner for npm, PyPI, and VS Code extensions. Detects GlassWorm and similar malware campaigns.","directories":{},"_nodeVersion":"22.22.1","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_2.0.0_1773920027625_0.29538034517068423","host":"s3://npm-registry-packages-npm-production"}},"3.0.0":{"name":"supply-chain-guard","version":"3.0.0","keywords":["security","supply-chain","malware-detection","npm","glassworm","scanner","cli","github-action"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@3.0.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"e4c0f52a5333d66b6b6e4563b4783a67c1b5de96","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-3.0.0.tgz","fileCount":56,"integrity":"sha512-sJxkj5VrVtQ6TYOmoDU7MqdFT4bPaYp4FpbRNW3YuPZRMuuTaQSAhahflFaX4g8FlykIf/ak1pyrOBI000B4iA==","signatures":[{"sig":"MEUCIQCQQAnC9+d2qMGZZBfBOmxubPWcpDxaHb2kQCHxB8fgawIgN/rdzfTARF0Hre2XEvn83oxvCh88T9bl49+Oq3pJcYo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":402540},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"9a539a5d5b2b4a33e5548620d9266e41222b62a6","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"elvatis_com","email":"emre.kohler@elvatis.com"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"10.9.4","description":"Open-source supply-chain security scanner for npm, PyPI, VS Code extensions, GitHub Actions workflows and Solana C2. Detects GlassWorm and similar malware campaigns.","directories":{},"_nodeVersion":"22.22.1","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_3.0.0_1774484578286_0.15419281461716672","host":"s3://npm-registry-packages-npm-production"}},"3.1.0":{"name":"supply-chain-guard","version":"3.1.0","keywords":["security","supply-chain","malware-detection","npm","glassworm","scanner","cli","github-action"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@3.1.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"a5ec1697ebcc8bbe0cabf46a24d63e6cdc0fb8c1","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-3.1.0.tgz","fileCount":56,"integrity":"sha512-YQbljbK+OB4izd6YMkBd6tGDRX16MbZAeRH+uoFzxCSJX0kXBS98j7WHcFy4fUpuKBLC7xSofSXDckkRX5casA==","signatures":[{"sig":"MEQCIFsrMe9Z6Jy7wcyLVKVcDhcf4IBjQNvyCQWNYA9PqhJ1AiAG1ZoKuUq296/PhvVIDG9U8UCjluPe5t9kVBl93Hm8Vg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":407471},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"09999abc87cea74efadd03b3bceb16143849d010","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"elvatis_com","email":"emre.kohler@elvatis.com"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"10.9.4","description":"Open-source supply-chain security scanner for npm, PyPI, VS Code extensions, GitHub Actions workflows and Solana C2. Detects GlassWorm and similar malware campaigns.","directories":{},"_nodeVersion":"22.22.1","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_3.1.0_1774518861884_0.632134623001823","host":"s3://npm-registry-packages-npm-production"}},"4.0.0":{"name":"supply-chain-guard","version":"4.0.0","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@4.0.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"e798f4eacc25ceb80dcdee79560de350d148360b","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-4.0.0.tgz","fileCount":80,"integrity":"sha512-KcWxVGWLby+DA3w1kst6Q+9SLLKBdGSkAMBP91/7D+0K25oGWdn35a9ySOaGW/1Xe7t1uX+C16x7ASPIJZsvvg==","signatures":[{"sig":"MEUCIQDqSgMkq2UbMkpXIO1NNJobAzWq+0M5ycztV5mn2C4pcgIgRyUSzZtDicMKj3P6QIS/sjZOFxFSQRDIYidaaEZPykk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":527290},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"5bb49e213bbe6b09e90bf3e94e6de72d08aa61b0","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"elvatis_com","email":"emre.kohler@elvatis.com"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.12.1","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud and 110+ malware indicators.","directories":{},"_nodeVersion":"22.22.1","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_4.0.0_1775296752406_0.040050885147493664","host":"s3://npm-registry-packages-npm-production"}},"4.1.0":{"name":"supply-chain-guard","version":"4.1.0","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@4.1.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"8faf6e29b7fe2604d642ba544f143fd2fd3fd25c","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-4.1.0.tgz","fileCount":88,"integrity":"sha512-rnMUc8qXzW1uyxVSUdGEgzNHo45BL+DUx+CmAL080Vkpiz2FiteH32r1btjwzp9y6prTnm2DvipKAe4wpbQenw==","signatures":[{"sig":"MEQCIFcwIzyqti/23SKsyRsmjYMFD8HjytQYf+6NzW9bHWqOAiAf5rMpH0gmhHg8u2OZnqVAm1CnToYZK8+ZMcsVCqvxeA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":596264},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"169c2f29f0cc4bc054918df8b5ef07e69c662aee","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"elvatis_com","email":"emre.kohler@elvatis.com"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"10.9.7","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud and 110+ malware indicators.","directories":{},"_nodeVersion":"22.22.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_4.1.0_1775327301488_0.8014024707948211","host":"s3://npm-registry-packages-npm-production"}},"4.2.0":{"name":"supply-chain-guard","version":"4.2.0","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@4.2.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"9a6c58acc8175ebf2f0ab7bff5880b4a6b6982b9","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-4.2.0.tgz","fileCount":112,"integrity":"sha512-nFoAQVK6+a3YAu5knB/OZSJTj/sIL8nEewJaLY4T7/m+/LcJR3pSXzvhK9sQjoxTI56kuwogaCCvnZDkXHkPcg==","signatures":[{"sig":"MEQCIGWzOXDA0HQqTnyj3UIOfyLJgnCFY1P1InDAW4huluSFAiASUAlTjaVI41PvbGL+rAge/rol+EiDQDfmcxPTPfTDaw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":683897},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"209da700a0b14f6b5e00a1b5eaf7d2c9aec0e5f9","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"elvatis_com","email":"emre.kohler@elvatis.com"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"10.9.7","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud and 110+ malware indicators.","directories":{},"_nodeVersion":"22.22.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_4.2.0_1775328237796_0.7965642337657273","host":"s3://npm-registry-packages-npm-production"}},"4.3.0":{"name":"supply-chain-guard","version":"4.3.0","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@4.3.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"6e1e200cc88f7b5233027868465421b89b8eb713","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-4.3.0.tgz","fileCount":112,"integrity":"sha512-ge2VUyL0i0UCCBCKTY35PVPUuxTKq6E72YyA+dJ4NkKxaxkbGQ0dru5355elkCK+l3p8fZ6Qmdv+kiK+m8UsQw==","signatures":[{"sig":"MEQCIB07FNfyNe5QOkojfLvNDOuiHwQSult55b1Hc72/w/75AiAlg7ijkP38j826JPgko98Fy+cwuFoHOwfX9JVa7QKmpA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":682898},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"daa0b6c740380bd0a581bf6ae7cd3dbc49717255","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"elvatis_com","email":"emre.kohler@elvatis.com"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"10.9.7","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud and 110+ malware indicators.","directories":{},"_nodeVersion":"22.22.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_4.3.0_1775328623365_0.8214429800478735","host":"s3://npm-registry-packages-npm-production"}},"4.4.0":{"name":"supply-chain-guard","version":"4.4.0","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@4.4.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"bedce0723622ba00d90b273a70828cbe31dcf927","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-4.4.0.tgz","fileCount":120,"integrity":"sha512-LmS94ilWSvnUkCcqhcwdocW9gT01yL/pqXAh0hkVWyCaOYOpRKepWHnbwpPzkQHmHTmWNvFsn2wEYar7lG0Z8A==","signatures":[{"sig":"MEUCIQC49AFocqlLxHG1lLblDBatPeQ1+xr6X6AxLgKkqu2jzgIgUBZX4SEoNgEenHsVgPkjHEPuOK9vqTYC4WaVGJEvLYo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":719438},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"c7a81acad2c386ecb90d49b488f021e5175ba199","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"elvatis_com","email":"emre.kohler@elvatis.com"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"10.9.7","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud and 110+ malware indicators.","directories":{},"_nodeVersion":"22.22.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_4.4.0_1775330361808_0.876034849567825","host":"s3://npm-registry-packages-npm-production"}},"4.5.0":{"name":"supply-chain-guard","version":"4.5.0","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@4.5.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"129c1669a564c13cf29a44fa7d02a7aea250c52b","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-4.5.0.tgz","fileCount":136,"integrity":"sha512-FpvbbQatkgbmUpdtHSXNeZ4Zyod4URXKML0gN8D2skkOf2Uy/nW5ABnSz0rP/40FHQAgkeInC1FgkwgLk8zJcA==","signatures":[{"sig":"MEYCIQCJduB2ceMAt1C9a9J7efDu3o0q3cuQMSfUbDFyjV0IfgIhALMDxG6Y/Czhbc7MJsBBM45YwagD/3pXIr2UR8O1KZP2","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":768659},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"75f4a5456e16cd1720c810d5b4170e81a5ab89bd","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"elvatis_com","email":"emre.kohler@elvatis.com"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"10.9.7","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud and 110+ malware indicators.","directories":{},"_nodeVersion":"22.22.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_4.5.0_1775331027023_0.6730549152170247","host":"s3://npm-registry-packages-npm-production"}},"4.6.0":{"name":"supply-chain-guard","version":"4.6.0","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@4.6.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"1454cabb4ac88b9f6c5c258081f28f18be12c664","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-4.6.0.tgz","fileCount":152,"integrity":"sha512-flD3KyLUHULHwScUPJMynffUPimwIxrOyIzWaWkYR3RFNbHBsMCyiChsBFflWTHkH3+Im7Lzz8cnucACMDmp7w==","signatures":[{"sig":"MEUCIQCvrMk2HM2omNV8qFtE58UwD6y4hoHlPhnaoJNVmveyrwIgczM8W+hnB7ipXoW1OAZfadsqeIY/OWp3z05KLL12Ou8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":819964},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"bda0f6264c9045d4ee1c86a371bad6d3930f5387","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"elvatis_com","email":"emre.kohler@elvatis.com"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"10.9.7","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud and 110+ malware indicators.","directories":{},"_nodeVersion":"22.22.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_4.6.0_1775331484025_0.13318009870610226","host":"s3://npm-registry-packages-npm-production"}},"4.7.0":{"name":"supply-chain-guard","version":"4.7.0","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@4.7.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"00de9bfcf53ae5d3abd9b1e1c6b586ec2c94cb74","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-4.7.0.tgz","fileCount":172,"integrity":"sha512-wbKq7c/bcy1GKAEErgmVFqjQvfSJAXlENSd8GRyRlwrKIlOih8ohTB1jqWPA4cwV3/6z+BLu6pEHqcMe/i++jQ==","signatures":[{"sig":"MEUCIQDXwDFqDhWTK2pfvIhGQRPsl/XrqZKzHQbsPFnJIySOHAIgR+DNE/R/lbX8yEZByJBApacautZ8GAs2p7Q7l+fiLt0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":870868},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"2898424344ff4e800fc5acf46ed8b758c11044b3","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"elvatis_com","email":"emre.kohler@elvatis.com"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"10.9.7","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud and 110+ malware indicators.","directories":{},"_nodeVersion":"22.22.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_4.7.0_1775331933403_0.9011188935783137","host":"s3://npm-registry-packages-npm-production"}},"4.8.0":{"name":"supply-chain-guard","version":"4.8.0","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@4.8.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"bde6033c9e0c9ae779d45c6165a50a24fc10c481","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-4.8.0.tgz","fileCount":192,"integrity":"sha512-ZVMVbC8wsfMdcDsdbmn2gdZ0kLdILTCQccsJaNCJGwovo/EjySzNmrBsnTTlyjZCN4e66z+flsRx7cqvj79qkA==","signatures":[{"sig":"MEQCIDHVtvV+RaVK0RzEGLNtUe6wSEAvVPUmr0UMQfseKYoKAiBQ05Kmq6uNr+8kJM5CzbL74YbCB5MVPXAxdmaoPi+c1Q==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":915804},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"678f46e13bc3e3b3fe37ca6a07ea99a81566ece0","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"elvatis_com","email":"emre.kohler@elvatis.com"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"10.9.7","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud and 110+ malware indicators.","directories":{},"_nodeVersion":"22.22.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_4.8.0_1775332453666_0.7113095272755918","host":"s3://npm-registry-packages-npm-production"}},"5.0.0":{"name":"supply-chain-guard","version":"5.0.0","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.0.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"9235b02095ec157163e908e730a9b9c871c34b65","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.0.0.tgz","fileCount":200,"integrity":"sha512-nt64r6K0u4jkSBHwdMPmOnbYmXVtTf1S7fN8i/h/Wotikquch1iTiyYeQrE5vYtBtjmgluB19dosQo+aZpD/jw==","signatures":[{"sig":"MEUCIQDT6NhRFYycHoB8OKxYyezZlZt8LLFrO6owCx3ovCvHFwIgG22qk7QF4ENrWH9e327RRnt9gkLGJTB2ddrF0Q2QEfI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.0.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":993992},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"97d4eae06178d26ca12c95b7081e3976060d6bb0","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"elvatis_com","email":"emre.kohler@elvatis.com"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"10.8.2","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.0.0_1775579490020_0.34968646578280094","host":"s3://npm-registry-packages-npm-production"}},"5.0.1":{"name":"supply-chain-guard","version":"5.0.1","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.0.1","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"5b22517b761485cadacbbe7caaed042a88eb8496","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.0.1.tgz","fileCount":200,"integrity":"sha512-6KsFUoe066Wo62JpM9bZOAukDmkZHkdF+DX8wDog3rw40wpop8MN0xWJxRSjHHOEX/vAhcmUIEaWEubEuSXTpA==","signatures":[{"sig":"MEYCIQDWH0+qrArT+ZN21Ua0V/nwfETP+k4GyldYrKCVmg4bQQIhAMH0uRC81/NYlgV/A6pU2Kodu4S3fh+hhbpseXs6PRds","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.0.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":995411},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"668886afba4af38bf65e171eeef0671939182e88","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"elvatis_com","email":"emre.kohler@elvatis.com"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"10.8.2","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.0.1_1775580804303_0.13033334099940563","host":"s3://npm-registry-packages-npm-production"}},"5.1.0":{"name":"supply-chain-guard","version":"5.1.0","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.1.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"41c3a8e4e2b62a0d5f8924d07ec392c7e975f148","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.1.0.tgz","fileCount":200,"integrity":"sha512-/3zqt8qKKqopMmKoiwcZ6BDohAf5ogwrNl9x+iEW5g1/mIJ1Rzmb2rwk7z6c3fMsQxMvl3PDWQu8izgV8DTt8g==","signatures":[{"sig":"MEUCIBL01NZOyTSRPCfvDV+py8ZHzd3kVCt04WEPGICbtOdsAiEA9XF+xAAZhaDOGJuLUie8wzSI61W+FKrz0h6oAdADqfw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1013395},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"5e32681d7fd5beafd4acca6e928f64cd1a64c5ae","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"elvatis_com","email":"emre.kohler@elvatis.com"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"10.8.2","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.1.0_1775583834559_0.6650972456516133","host":"s3://npm-registry-packages-npm-production"}},"5.1.1":{"name":"supply-chain-guard","version":"5.1.1","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.1.1","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"02a6ac71b5cd76a397a7f5067b4be8e531ad6952","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.1.1.tgz","fileCount":200,"integrity":"sha512-w1OW8aW7+CTjU+MKgq2TNmV+9N1KgU1wTQvrdYkbQg+PFJSb5D+1N/OaWG020VlJnkffy/5vMOVpUzCL9x/HNQ==","signatures":[{"sig":"MEUCIQD8GzEBEOq8Kk3NrA2ns5S8HTmFpa9iFdm3skaushlECAIgYYOESe4rscgpZh98UbxwT53AQvAtyqa3Yb1hSaAr8+c=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1013765},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"036660962ad01808aa985fd55a68f58856a63863","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"elvatis_com","email":"emre.kohler@elvatis.com"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"10.8.2","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.1.1_1775583920715_0.4776070589936108","host":"s3://npm-registry-packages-npm-production"}},"5.2.0":{"name":"supply-chain-guard","version":"5.2.0","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"12a3169c0cb4df954715707552bf11cbbda4ff9c","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.0.tgz","fileCount":200,"integrity":"sha512-294EIAlnpT8t1WGHAFgp0BH/bne+D375AcjZk2N2IShSK50S5X8nQf2ta6N8XMB876Fy18AGhFfQA8drdt2hfA==","signatures":[{"sig":"MEUCIQDokMR5eo6vsc8GanPwSUqWnNtXBUxqaiYAjpVZgtPqkQIgO0mrhhqmKXVzHm9Vw5HBiZHwgM618oMFjtF+d8y/K5g=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1028997},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"4ba01d4c96c0814e7ab56e856dddd75539681385","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"elvatis_com","email":"emre.kohler@elvatis.com"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"10.8.2","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.0_1775656182225_0.14679237732214023","host":"s3://npm-registry-packages-npm-production"}},"5.2.1":{"name":"supply-chain-guard","version":"5.2.1","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.1","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"20a728de4836d292f21e1936569d4359e966ae8d","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.1.tgz","fileCount":200,"integrity":"sha512-1UYGzD4ro/ORD36NreX2sbfVc6ibZhfY6TGVDOs2Tfh+F3UI9eZaZFc6e5uSEJI85sHJtVCVK+80KTONDUsRTA==","signatures":[{"sig":"MEUCIC2WF3Kuw5twp+5EjwOV5TTvJyA8PNIlXNK8Mtw+/hS3AiEA4Giwlc7zFFrnD+rfHAiQRoUi9xieoPkVsMJNjo4IbCs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1033073},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"67062996941554c37e1bd573a3e76bce4faf2ebb","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"elvatis_com","email":"emre.kohler@elvatis.com"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"10.8.2","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.1_1777180221915_0.014859500576756224","host":"s3://npm-registry-packages-npm-production"}},"5.2.2":{"name":"supply-chain-guard","version":"5.2.2","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.2","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"2f182ecf5a5e4df0719ed1462670157ceb3ef38d","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.2.tgz","fileCount":200,"integrity":"sha512-MSvMPJ+sU5CH7Ip351Chx36BvcA9ik/Ljd0MXsKjMFlUeKwMARqFMGUPyxzquVpWmDAQ4qvXRLI5kd9wKLskFw==","signatures":[{"sig":"MEQCIHTAcqkTe99XFKF4LQN0OfF61CpYv6mbBv/8Xzgc0tZfAiBXr/Hyh9JmFgR2gUSMBy/vONi4YRVTar2slNHJZRojfA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1040810},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"f1ece8e6c249fa7855d047629e7d8d4f0911aff0","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"elvatis_com","email":"emre.kohler@elvatis.com"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"10.8.2","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.2_1777181098138_0.35987456780955784","host":"s3://npm-registry-packages-npm-production"}},"5.2.3":{"name":"supply-chain-guard","version":"5.2.3","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.3","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"0879d50e2a2e4f43d8956b5db8be5822f79e4cfb","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.3.tgz","fileCount":200,"integrity":"sha512-PKGleGI+npGWAETYRX52Vj92BxbcD8TLemxIFkHP54Aw7PY4FSWniEVEFbMiMKC2wO88OSW7TJzttdBGa5Cxmg==","signatures":[{"sig":"MEYCIQDzKDd8ziPpafjA5eEF2Ff4rk9xj/7u9R0wVyBmAuTtYgIhAMLKtHl7rU3H5Efh6lC+qW3WwmtaXMrMazRU676kDdZd","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1043115},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"273328d6b34cf1e4732045477f391154496b0647","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"elvatis_com","email":"emre.kohler@elvatis.com"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"10.8.2","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.3_1777181302867_0.1232631711268628","host":"s3://npm-registry-packages-npm-production"}},"5.2.4":{"name":"supply-chain-guard","version":"5.2.4","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.4","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"1e597440f8ffa3d24d5d8a48e75ebe7dc45d08b7","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.4.tgz","fileCount":200,"integrity":"sha512-FpsLmmVVpFQu94Zp8Nnh3AfDZknS0AoTLgdVIYEpuk9fw3V8kvMapNt1bTwGXuG0TBRMbhKgPaDuhCXWbcW2pw==","signatures":[{"sig":"MEYCIQCON579fOhe068+WTi67rFjI1XfyARu2CHnBOoKOeBk+wIhAOuJDvG+hfAJ7VqDUrDWJHCuGf3VojAKabqYcjMoupkW","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.4","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1047930},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"a38bde9ee6c7dbd084d6817fe51a50e6ad81bc1d","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"elvatis_com","email":"emre.kohler@elvatis.com"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"10.8.2","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.4_1777525862489_0.6995745755548892","host":"s3://npm-registry-packages-npm-production"}},"5.2.5":{"name":"supply-chain-guard","version":"5.2.5","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.5","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"2d2b849901eec51c59fd59afa5f22cd01cb79221","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.5.tgz","fileCount":200,"integrity":"sha512-HSYXRSvLirOke5XsoL+koWHktbdXs9xN1vqtVv1ENpwLMRPR6EpnsuueLe9JGqt3w2CuHf1kfdEKp/IWsVL4Bg==","signatures":[{"sig":"MEUCIH3AHiRl0CY2f9JlWODO4FQgYEBPqUyiVLL/R024/yTiAiEA+5aHzOmiVgssg6zoH0ltLsNY8hmfN1XQ/NLTLj0XdME=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.5","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1053998},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"acf091af3af16d77b50300c53123cb71fd87d161","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"elvatis_com","email":"emre.kohler@elvatis.com"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"10.8.2","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.5_1777623096927_0.8748526903085767","host":"s3://npm-registry-packages-npm-production"}},"5.2.6":{"name":"supply-chain-guard","version":"5.2.6","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.6","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"135882b4936c1a8a1c134f0bb822f72e402dd24b","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.6.tgz","fileCount":200,"integrity":"sha512-Tj5oNGWvnQP0M9/HHvAwfWwtbF+ssbw1YgGAohmbJvz9mwvN0UAcBdTG28QUUgJqnOhPOKLPl15hb6tEeOU51g==","signatures":[{"sig":"MEYCIQCw0hctVRY1agm5n+G9YHV1JtxD71gITyNG3G6rK4Wb8gIhALeysp0Xb2urDcSb6rtXEjQhZEDVcoXIIMzeOs8ijH5v","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.6","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1065551},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"f467719ba9be7077820d9dd88bc19ed1dbd795ed","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"elvatis_com","email":"emre.kohler@elvatis.com"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"10.8.2","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.6_1777785180536_0.3733262412379956","host":"s3://npm-registry-packages-npm-production"}},"5.2.7":{"name":"supply-chain-guard","version":"5.2.7","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.7","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"3980935472f18109197a16a76bb7ffe2a45c7a79","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.7.tgz","fileCount":200,"integrity":"sha512-I8WGhyexTAZMAO71Pv8V8zs4TzbckRMYGJhhnq17Xe5/waDemfkU6KObWGMdzB51K4/PyORuK46sU2igyWYP6Q==","signatures":[{"sig":"MEUCIFdkpJhBv/s3Z0vjonU94UiihPnot/tlLGilp9yCm9LCAiEAkCTPfYUVynkE+nReXjZfDumpa4y0VoLxnWFg2jgCaZs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.7","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1066380},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"be993a9d28411148cd550c55ec8ec1cac2cf987c","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"elvatis_com","email":"emre.kohler@elvatis.com"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"10.8.2","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.7_1778081907987_0.592817023165015","host":"s3://npm-registry-packages-npm-production"}},"5.2.8":{"name":"supply-chain-guard","version":"5.2.8","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.8","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"6ed21c55da238841a02f6af05a2e80c01f164196","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.8.tgz","fileCount":200,"integrity":"sha512-xvycvR+ZMhMpUZZpnjOcC1zm6Swjqe0sLOanMvKcOxYWgV5jG2JjU5+5CTIXH0GXk1WNKDWJXpbtsv/HYXKibw==","signatures":[{"sig":"MEQCIBxYwtx10nlwpd+2bnLpWhh3StS6beDeB0ZtkSsMSTWnAiBx9ZJ2QFv/idDSHlaZJNAJTSgtBy5VoLu7BaCVd0U3GQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.8","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1070758},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"a20729e44184c506dd964710448835d93f70e7e2","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"elvatis_com","email":"emre.kohler@elvatis.com"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"10.8.2","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.8_1778217563129_0.04408736498727639","host":"s3://npm-registry-packages-npm-production"}},"5.2.9":{"name":"supply-chain-guard","version":"5.2.9","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.9","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"8fcf8006ed7b1a9c16521907f5dc3e9536e5d4b1","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.9.tgz","fileCount":200,"integrity":"sha512-+OVbfGdnKGFDZ7kCr9iGQw/k07fJZfCbWIw+LDoq2s78Ul4xDyjGk/JQkx5qPS35ifo/ABIXcbQbrj607NtsyA==","signatures":[{"sig":"MEUCIGqrnY55Rk/7gBftw+fCjJ0PBZIKIThZGT/9Ea7ezUU8AiEAsvNhzqGP92kvk+Cw2c4f3GfvX/1ckGa4qjG7R5m0s/8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.9","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1076358},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"469a6312d3b3306f7004986179d3de8816be0074","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"elvatis_com","email":"emre.kohler@elvatis.com"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"10.8.2","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.9_1778303717670_0.6892130054577907","host":"s3://npm-registry-packages-npm-production"}},"5.2.10":{"name":"supply-chain-guard","version":"5.2.10","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.10","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"eaa8f2813b205724e6b1fe698f470b52bd58569a","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.10.tgz","fileCount":200,"integrity":"sha512-yCnyBwClMBq453tm1i1/oRo68rLAbx1q2n+ocllCI9dtIcUTxrK7/KMrYkX9V8ewyQ9seFpZ2RYkFp497e+f1A==","signatures":[{"sig":"MEQCIDtVPf5nGGRlUQSFWuon5b3ms6HLyQAQ9FfEK95IUnvxAiAn0WiMwadZLcP1Pt5WP4nREzWOy5bygafBififlSQuVg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.10","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1078554},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"046efe01be82621037c419dac0cdd4af4c0f214b","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"elvatis_com","email":"emre.kohler@elvatis.com"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"10.8.2","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.10_1778389711183_0.5605717250652928","host":"s3://npm-registry-packages-npm-production"}},"5.2.11":{"name":"supply-chain-guard","version":"5.2.11","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.11","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"750b6b96ccc00ded96afb487bd51a9a1d3a7c230","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.11.tgz","fileCount":200,"integrity":"sha512-BO/mc2Hifnlhb2xwccUQB7JeRtkLq5f5OnmhyQM3th0hUSdV7vqa4QDVabu3fsRVc3Easdqf/15RxclKAnp5HQ==","signatures":[{"sig":"MEUCIQDTBiC5r0yi7vyTHvyEawgJV0snk2n0QSmKYJu4ay133wIgTfKmimFOOAkeXDmJOEBBx580BVojOHRM2VuNrtn+b7I=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.11","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1082189},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"cb97a3334332d43714f09710b3d9b85c542d0396","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"elvatis_com","email":"emre.kohler@elvatis.com"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"10.8.2","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.11_1778562512290_0.8973556668803973","host":"s3://npm-registry-packages-npm-production"}},"5.2.12":{"name":"supply-chain-guard","version":"5.2.12","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.12","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"5af514c3a88e23aaba6252734ce0bd2474a0f6c6","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.12.tgz","fileCount":200,"integrity":"sha512-B5qGL7+FRe9zUrWGcye6G04Xo+9XWE75cGj1771ZwDw/kmMPtbFKvL4LpKr6PlQY4Lz7stF8qDJIxmmQpPAaew==","signatures":[{"sig":"MEUCIQCF4CFdM60bOjoAu81zYutJKEwySKUDlKu3LApRzAhw7AIgS1cDAGFHfw816wM+I0l28/uSXf3nKF2ct/zvyAYsTA0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.12","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1090047},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"aa6de7d6960a5a28eb6bc3784e66615805468a9d","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"elvatis_com","email":"emre.kohler@elvatis.com"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"10.8.2","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.12_1778740800766_0.12190739433075382","host":"s3://npm-registry-packages-npm-production"}},"5.2.13":{"name":"supply-chain-guard","version":"5.2.13","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.13","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"e0db6b0086f764d2a6ff1feaebc429f52e00dd90","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.13.tgz","fileCount":200,"integrity":"sha512-MCVt129D+Mji7SJYX7QHpNf2wjL177/c16UJV1CDzIe9W7ygFNThVuDZaZ9rhIIUTa83mJzPBvzvpk8BhF1jAw==","signatures":[{"sig":"MEUCIAdYM8zw62yKJd5LZoA/VjeycowutAxvUmZXCNf1oZ1eAiEAmQuwYVAjKXiZOH1eM3u4i8T2ESclXDRg1uJkfRHWT1w=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.13","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1093287},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"eade9e6d9ee66699aec8b2029da6b7ff55e9abe3","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"elvatis_com","email":"emre.kohler@elvatis.com"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"10.8.2","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.13_1778908094073_0.09436445263746873","host":"s3://npm-registry-packages-npm-production"}},"5.2.15":{"name":"supply-chain-guard","version":"5.2.15","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.15","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"26d796ad173b39490965572dfddafa49c0bd6caa","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.15.tgz","fileCount":201,"integrity":"sha512-yFeXeHEL+bbNiJDSo52FcsgfBwrIn5mxJjAB2ugXIqrE9e+ws24H0vXsXJGEuK4r1bN3hRIx1280YXMY6nZpEQ==","signatures":[{"sig":"MEUCIGm9zBB6gCXPe2aVgDBoeqTH3WEC3lAynxPazys8hy7ZAiEAwHoB783vvX2CuYeO0jgKsdM462hT02DPZxdGTPWBZLU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.15","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1117405},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"b1c0b5ad9b1e63f47143c7d6717a862fd2c31005","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prebuild":"npm run check:changelog","test:watch":"vitest","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.14.1","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.15_1779291449523_0.08596652069755262","host":"s3://npm-registry-packages-npm-production"}},"5.2.16":{"name":"supply-chain-guard","version":"5.2.16","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.16","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"6dccd3c8cd9ea8b666a6e66efd39e769a4d26bbb","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.16.tgz","fileCount":201,"integrity":"sha512-K8U36Fj6xbpbGVDB4cUBd6jfRRTp/H/Wn8ru+M/ZcxU8GSg1MBmQnbeQBHyDPVlOWPuGRMXy3Kb8NNS35dazqw==","signatures":[{"sig":"MEYCIQDZ6RjTmlXSSVDn5/QFNd/+6Fbq016AGu25l2QJQ3S/qgIhANYeG4i5YvGtK7NRSUMiW1IjMdyxbMSqOq3O20ubZHiV","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.16","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1120123},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"67f201ca97a8fc1c4d6cdf6b382e7336dcc924d6","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prebuild":"npm run check:changelog","test:watch":"vitest","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.15.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.16_1779430330647_0.3042209704300749","host":"s3://npm-registry-packages-npm-production"}},"5.2.17":{"name":"supply-chain-guard","version":"5.2.17","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.17","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"b686eece808b9d6ffd7ff8a5a28a784f4c54412c","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.17.tgz","fileCount":201,"integrity":"sha512-KLaycn5OYvuVw8dmglhu8ikR69QhnirZYbDt77FoxTdeLjmtc8nAbdWnG7p6W4rRRYZdeJriZnf6wIOTYLUX8w==","signatures":[{"sig":"MEQCIGj+YnIZTLqOkkZhaeXljnMlO5sFv9q7JZqgeMMrccgsAiAEG40GwEBB8LWFWb096HqY0e5qUc5KchOcyu1wIgt0gw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.17","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1128997},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"efeed13f3130ce2f73d524352d434c43a705be40","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync","test:watch":"vitest","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.15.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.17_1779531109911_0.9870145478617187","host":"s3://npm-registry-packages-npm-production"}},"5.2.18":{"name":"supply-chain-guard","version":"5.2.18","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.18","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"79c96bb29dabf0db7fa8f562fbbe3dc31513232e","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.18.tgz","fileCount":201,"integrity":"sha512-icMlYThrSS4w+vDv1LcOMV+ANjI0Gnd+X3HCGttGJ7W43hF0FcHED7uC4GUJmtPkHgf5PlNP9jLIX2YLl7l8yQ==","signatures":[{"sig":"MEUCIQDsXl8YcOT2zXjLJyu6JlomNVhHy4hgOT4uPB2l2+DRyQIgc9H0NkJPbyS0CFeU7e5lvXKqo/v7AxWHqJHJ6aDddTw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.18","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1138875},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"f9819910afa2231f4fd296177428d963344d8e78","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync","test:watch":"vitest","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.15.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.18_1779606650994_0.051949733020422606","host":"s3://npm-registry-packages-npm-production"}},"5.2.19":{"name":"supply-chain-guard","version":"5.2.19","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.19","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"598b2d53d788d9169f89409fe0c016b44f866898","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.19.tgz","fileCount":201,"integrity":"sha512-Mj+/KPFeVBPyuXTEW7YWUculVqXw918w1hduSyf0kaU23oakgCYw1wKIkr/VDJAL0oZ56h7R3bPVXsnCkL/zMg==","signatures":[{"sig":"MEUCIQDz07WbmzlyVGb/9St+G9uJi0qz1v6QcYGmZPxtgSInvAIgIrMVUg7zBlbzYF+2v6RrTBqbsJcj/OTZY15bTRHx6Vg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.19","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1147402},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"d0c3c2965b07bf458da3149045d609f1f374bf3e","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync","test:watch":"vitest","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.15.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.19_1779607995857_0.27179940163760996","host":"s3://npm-registry-packages-npm-production"}},"5.2.20":{"name":"supply-chain-guard","version":"5.2.20","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.20","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"b0612ac0be73758497d7c2001b6ba671cce0caa8","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.20.tgz","fileCount":201,"integrity":"sha512-8PJQ+fMFWHK4ctD4ewCP/Ni1Yke2pD72gh+7GuVnjbldpojKishBo/+GhllN5TOjpYBFDVELEvMpZ6vpaQ/4lA==","signatures":[{"sig":"MEUCIFjXomDCBdtvNpOYVW2lDkPbYbh1XOprpSLSKtKpS+fGAiEAsVp7oStv46f27jfBPO3sL/UZUD+NACP7lnxFT8tRgNc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.20","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1152368},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"299989bbf23d0a1783baadc8d2d84add765939cd","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync","test:watch":"vitest","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.15.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.20_1779609600952_0.36026312931664695","host":"s3://npm-registry-packages-npm-production"}},"5.2.21":{"name":"supply-chain-guard","version":"5.2.21","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.21","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"fc3a69bcc51c33d91b923543c7c1f594227ab9be","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.21.tgz","fileCount":201,"integrity":"sha512-0HydreUUp7CGYb1QR91nZCZwJkj+OA1GZvOMspPBJ2cCUW2V/6Llp5YZSx17rj18hZxL1ZBIbUvl4d98p2VK6A==","signatures":[{"sig":"MEQCIAcqPq10tsJ3t3SBMv44rTdSGzRh91Tgk7vpzwDRVJ0HAiAArE5/sY4BaReu/pfLrLz/5p5wsHtGTlTzt0i+L0RVWA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.21","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1159501},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"5562adaf64b7e16e6196ffa585864a657b760ae4","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync","test:watch":"vitest","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.15.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.21_1779610770513_0.03952066833610979","host":"s3://npm-registry-packages-npm-production"}},"5.2.22":{"name":"supply-chain-guard","version":"5.2.22","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.22","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"e62472b8d2b52e40594f22554235ec3f01cc0c12","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.22.tgz","fileCount":201,"integrity":"sha512-Exp1G2+MZVcR9Wv6B2rMqi9/+3ilRQ+6y4cBcoGivV/7mWsMJ1yqkJJgosLyAlhH3v+Q7S923Jf0OdUX5t8agQ==","signatures":[{"sig":"MEUCIQC4ppySxne7crE7UQmK5MZ9J1sN2Q7J4gzxDmJdp1of3AIgGDO1uFeTD1u1k5T9CrErYa/2rjRWHAUjSQXHOIAHVX8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.22","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1163419},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"1aeeac569f7e7af603900d8e9d581f6541f1a564","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync","test:watch":"vitest","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.15.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.22_1779625110563_0.9299763094399225","host":"s3://npm-registry-packages-npm-production"}},"5.2.23":{"name":"supply-chain-guard","version":"5.2.23","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.23","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"c2eb81434b9b03343c003c4d544eb94fabca171a","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.23.tgz","fileCount":201,"integrity":"sha512-mphXABl1yaGCHFHYikxYGLivaAbhDdAQOHKMLam2MIqIPUlWGpIEemCjQ/wxom/N9HSuYN0OTduNMKMBYAz3mQ==","signatures":[{"sig":"MEYCIQDJ/3zEllHpzySqfuP+nXMZsSYMbjiZrw+hja+0DJKWoAIhAI0bRXfTt9y83NLGUCfwr+/8pL6Jn/RK+D3KId0FWVbQ","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.23","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1165093},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"f14d9feaebd4676a9fb8b9b7cf3b769f74ba2ecb","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync","test:watch":"vitest","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.15.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.23_1779625387900_0.7459981714493391","host":"s3://npm-registry-packages-npm-production"}},"5.2.24":{"name":"supply-chain-guard","version":"5.2.24","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.24","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"e3d9e47af7c90f7721cc7aa62f0e817a74c567a1","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.24.tgz","fileCount":201,"integrity":"sha512-1jaBdFFjDFESr4AVKfGpYq++ryTik/Xp1EO82mQclCOJ5rSdSpnvB7zgAuUXQvdq5/1wtSjFdPuSf/Mvo0+Vtg==","signatures":[{"sig":"MEUCIEXHNhDtqhwUZgvOKC/T++rv4gHUDA76KPmLV+6gTmFcAiEAtUK660lvEYX6IVB/iWAT2+fKNlt5QHYY/3LvcBS++7g=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.24","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1170311},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"ef8672ff5c47c8786b62c7da5c76e9a1821c7a03","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync","test:watch":"vitest","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.15.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.24_1779625741534_0.15577409360415362","host":"s3://npm-registry-packages-npm-production"}},"5.2.25":{"name":"supply-chain-guard","version":"5.2.25","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.25","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"8ba05006d80a1ab4cf3da3db88d8bb05e1e742b7","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.25.tgz","fileCount":201,"integrity":"sha512-+JSQWPHoY1KRKz08m16/U8PcIc5+dsuZLiaGo4lRKEUKgrcEtgGXfZEMULef0zbr2BGPu5tHJACqySFw4YtkGA==","signatures":[{"sig":"MEQCICwXtCgXJcfT5hmOjrJFYH+da7kOXN6+cva2dQ7aQ0h7AiAlLZEsuzP8uzy8YR4WGE54mX+5S7RQlQBtn4kz/yu9gQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.25","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1193027},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"6e06aa8c729ed40879abb215c1e02a4d6e938aa1","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync","test:watch":"vitest","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.15.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.25_1779730185336_0.6607802357580423","host":"s3://npm-registry-packages-npm-production"}},"5.2.26":{"name":"supply-chain-guard","version":"5.2.26","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.26","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"cbb83657c55a5fbd522b209ec5e0ac10db3b4fe4","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.26.tgz","fileCount":201,"integrity":"sha512-LOmFfCbv0v36j136M9W058bNgVeu7ulYkgEI8AppARxAOwSYr/qo9j7r3CPt+96eE5STVldlxuQdCw+DeMe8Ag==","signatures":[{"sig":"MEYCIQDIlNlFHI9VHXoHJl/2uiQQ9wHlBIuzW8jVvlM5dKHVvwIhAKEQsZxdJ3e5sEesN0hmgRHgQu5wtd7ft7jFkdEqaaIE","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.26","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1197274},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"a058528725662a23b6f3af3cecd0ce266215b509","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync","test:watch":"vitest","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.15.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.26_1779733172813_0.27958304196916806","host":"s3://npm-registry-packages-npm-production"}},"5.2.27":{"name":"supply-chain-guard","version":"5.2.27","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.27","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"0e87514bc5cc8e701b038c711ff26591057a6159","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.27.tgz","fileCount":201,"integrity":"sha512-qjyMUImUvbPRfm7ivBOgseY/le4ddbgM1zaQ/MbCcq1WRDAwtXeQj3Ks25hbLQTW2OA7mDEuHohIePsWYyAvYQ==","signatures":[{"sig":"MEUCIAhaOipfeOt4XkCfwYhcpG6jNYywDnk7eOq2151TMy1CAiEAy3dYiOkDUH390DPcNBNU/jdDp94mqojkaKVcBnCAezo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.27","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1204689},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"f62157ab953dca0cf35187a0320612687dc5817d","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync","test:watch":"vitest","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.16.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.27_1779982816423_0.28320635810679895","host":"s3://npm-registry-packages-npm-production"}},"5.2.28":{"name":"supply-chain-guard","version":"5.2.28","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.28","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"7bf3285508e047af54bff99e8e5e9bf5e41ad47b","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.28.tgz","fileCount":201,"integrity":"sha512-qFyqC1NVMVz+jwQCwfORkbCa+ulaMM5XyMFhoPh2dKUOrkY9KQ2tlkIeTv/OoxpGAnvpVsOGIF9u+kPzBBSnkg==","signatures":[{"sig":"MEUCID/YEPl/060RKZNU3A5+Vnpr32/Ys3SVX3wyW8K+nd0zAiEAmHS/+8GWahngjf0SgvgpjRQtvFyryWtw8ls30c3TJo8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.28","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1225336},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"47d2d52f12529a3897dea0095cb15b6637c3bf0c","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync","test:watch":"vitest","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.16.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.28_1780328357387_0.05349110672877133","host":"s3://npm-registry-packages-npm-production"}},"5.2.29":{"name":"supply-chain-guard","version":"5.2.29","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.29","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"46ef0f43a27ccd80b13c714f1b614f4f44e47a2e","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.29.tgz","fileCount":201,"integrity":"sha512-X4oFYkDS8vFhdGzIHfImDUUq2BWHtx0tBevpUajOnGtKOj/92pWH71/MqhuLNFM1S/ykXXlRRViB9cFNi8UEtw==","signatures":[{"sig":"MEYCIQCP9AdHswBF1B5QwVqChS7o/+HRerFP7CcIddzpZ/w1FQIhANnFDk31VRuudM6gGq5j16xQJgC7OwkUvnBU7CFmJG/6","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.29","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1230986},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"598d8e5dd6208bb9a1e39cd944656bb7ee390c9c","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync","test:watch":"vitest","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.16.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.29_1780384098782_0.5808401758067931","host":"s3://npm-registry-packages-npm-production"}},"5.2.30":{"name":"supply-chain-guard","version":"5.2.30","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.30","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"3d2ddb3ef67dd1b3c9246aaf0ab873eaf3ae737e","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.30.tgz","fileCount":201,"integrity":"sha512-DVPgFbmc4v3uiXgxcxmTVWfScdGrGFO/KRC3srLtHjkuSYVjrJRbd9Mi0+4MXyc7qqoqDpWP9OrO+RnL/KbhGA==","signatures":[{"sig":"MEUCIQDV4YGQt00AOdgbDxRgDmeUqUDCS+KQc/yBwoKbZGglkQIgVX9vBxwyzC9UUdxyisGGj3szXWqrl8h5j75ltp3Ns/I=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.30","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1235732},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"56732967c580cee3311dcc4bd597fb002ba4078e","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync","test:watch":"vitest","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.16.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.30_1780988803968_0.2844918375746721","host":"s3://npm-registry-packages-npm-production"}},"5.2.31":{"name":"supply-chain-guard","version":"5.2.31","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.31","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"2cc712fbb6b93c4dd6723a47e87101df3c6aa0ae","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.31.tgz","fileCount":201,"integrity":"sha512-UufhtAKPZ+tQ+qgzHdoDscptiYVLtwlxDMrjfEBrwzadRCYe5+JaKiMFRsqdxXfNPmDp3pyQWq3jZ2g3C2hAmw==","signatures":[{"sig":"MEQCIEJQCADHFtLdGnx7AyRq16WcYx7sYN2beCdg4HsIXJ/wAiB1BCHJQgqZVQ7NMpfh2OSeFa1bjv3yzeziUGhgHGAFCA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.31","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1240305},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"154c680b4eed010bc5a0af45a45ec1ccc99e78dd","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync","test:watch":"vitest","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.16.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.31_1781192283008_0.7571980572399872","host":"s3://npm-registry-packages-npm-production"}},"5.2.32":{"name":"supply-chain-guard","version":"5.2.32","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.32","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"1a989df4170f59c49f2ef2aec005827b27bfe020","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.32.tgz","fileCount":201,"integrity":"sha512-t/f2y+Y2BS/9d8JpSqW+Kwp8p+qGp0a1SSW3unsfBXz+xXZRADjh1UYfdRpKU6dmPxhdIQY2SgbfGxsUMn1abg==","signatures":[{"sig":"MEUCIBxLKBiBfXEkLTYsWUh+fitm4s1zJNnZM4gCbl7Mak+eAiEAz9eXv9llia4CxRkCmN9j42/dKSfTsL629Sfz2QORr94=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.32","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1244676},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"bd2890397565ee2658c815c07b73258f9d635842","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync","test:watch":"vitest","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.17.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.32_1781347695474_0.21669654470910515","host":"s3://npm-registry-packages-npm-production"}},"5.2.33":{"name":"supply-chain-guard","version":"5.2.33","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.33","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"283b00149dfaf89bb6880bb0a7936a4a110f3cc5","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.33.tgz","fileCount":201,"integrity":"sha512-7lDfhLLyvyWQRsdXsnCyctsS+ts4fRIvuxueyqWg3sUO0EYeedAYllsSzb/dszlXauvtqaulR9fsLrHDCPPppQ==","signatures":[{"sig":"MEUCIBFprADy4qqfskXprsfyjrGgGpbZ6za8eT+OhATp07Y6AiEApHOW9K+06LZBeHa5tMhPCfx81QcVnmQ59mjP+o/q8/A=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.33","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1246022},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"60ad761839b2d44333e0ae6bc81ac6f73c5cbf28","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync","test:watch":"vitest","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"overrides":{"esbuild":"^0.28.1"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.17.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.2.6","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.33_1781420184108_0.37446601035330485","host":"s3://npm-registry-packages-npm-production"}},"5.2.34":{"name":"supply-chain-guard","version":"5.2.34","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.34","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"61d9f248a4ff721bc42e665aacda4438fd3e2449","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.34.tgz","fileCount":201,"integrity":"sha512-fWu+MP54UTGmBOPWtqs+E3NtKBr3BHH06iDsqTTPHbiWKSfWRwfaJiB6WemefcuhfwsilrzEM4EDe4AA2NAvAQ==","signatures":[{"sig":"MEUCIQDhrjf5R0nGjVkWKN4ed90ShSZ/uEhPI0KHfx3fkec+MAIgZLgUWKiFO5JZkbynrP0oYJ/2mCOHJLk/z9EfhBVqrVo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.34","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1264297},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"e302e33beb23bc4c3a9a6e6454adf75b0b3e491a","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync","test:watch":"vitest","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"overrides":{"esbuild":"^0.28.1"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.17.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.2.6","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.34_1782018783933_0.47941456667703686","host":"s3://npm-registry-packages-npm-production"}},"5.2.35":{"name":"supply-chain-guard","version":"5.2.35","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.35","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"0005da3e37b643b7ee18d5adf05e07510f7f847b","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.35.tgz","fileCount":201,"integrity":"sha512-jJd42O2uumfodorHuh4k3UgxE8fP9QcEqiQyiBQqw/1OAI7ywm9gHmYSxkNqLYCa7aNPuOXGbFNPckhsEZlisA==","signatures":[{"sig":"MEUCIQDoizj6qSFp0GOF87byl0iGetiahMBzIUALs41qU/zvdwIgYwTUfkibs97sdFo73Nq9ey2EY2lrabE2UV78kPpc/ho=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.35","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1265203},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"89a0f2c97ff866b939b9adf8709d8b431683d937","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync","test:watch":"vitest","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"overrides":{"vite":"^7.3.5","esbuild":"^0.28.1"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.17.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.2.6","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.35_1782037216822_0.07338807437175987","host":"s3://npm-registry-packages-npm-production"}},"5.2.36":{"name":"supply-chain-guard","version":"5.2.36","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.36","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"8c59c901b9610a57bb2c0fa736975897661302cc","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.36.tgz","fileCount":201,"integrity":"sha512-1yxSrfzblAcOSODoiI9GZx78YUlErrPMldnkzP5RigmTk3laikW3hPBnLlEul1FrUhKtPR5yEYNsA1QifDH+0A==","signatures":[{"sig":"MEQCIASHRBYnIBarkugZ9kO5Y8NmkrbzmHYRcyFwW+5y/Q0vAiA6cvT7quQdu//dHhQOBZq3yKhzCcVK7bUg9VsYY2+fbQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.36","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1267725},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"12ad48df47c0a5766752726ef3b5de694cb11e6d","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync","test:watch":"vitest","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"overrides":{"vite":"^7.3.5","esbuild":"^0.28.1"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.17.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.2.6","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.36_1782364897487_0.2054604377555569","host":"s3://npm-registry-packages-npm-production"}},"5.2.37":{"name":"supply-chain-guard","version":"5.2.37","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.37","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"3dac1aaf95c57013fd07d334d0751bfef303ab77","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.37.tgz","fileCount":201,"integrity":"sha512-rvBMeG5s9NuDM9T8CBUPTaapuIMWPeGXMnWpSNdkRqDEaPhIe+SY53OKihtWn6Oc88dGpW+/vTaREYliTUQrqA==","signatures":[{"sig":"MEQCIEtva7J/dG4hl/91ZJWxJHNmPM8lxywwwV6/KnHIuMJbAiByIbKboJOztxo39nweFuQI6cK6V8A1/zFObA9zmkTU+g==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.37","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1268744},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"be1d718b17cc38e4bce7fa48579b7112e557943b","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync","test:watch":"vitest","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"overrides":{"vite":"^7.3.5","esbuild":"^0.28.1"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.17.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.2.6","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.37_1782536235720_0.7726153288502768","host":"s3://npm-registry-packages-npm-production"}},"5.2.38":{"name":"supply-chain-guard","version":"5.2.38","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.38","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"8c235034fd00721d603cee5a4623cb9ec04aa66e","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.38.tgz","fileCount":201,"integrity":"sha512-Cj98vj9P0Ns7WI/IOEAB6e2teJ86SSz/1oJ/mXL5Agvc3K4jSvD52Uano/6z4yhg6zjtfWbTo1t7ifDggUr7GA==","signatures":[{"sig":"MEYCIQD0BgGrxBYwpeJh4AVoOcd/oAFvAaC1InmuiddJQbG2IgIhANEbiiveM2q37e6tZUCUJPeEmSEiAEE6yu1wXxSNOTWW","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.38","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1271255},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"3694a5bae935459d1fa3d33d4bc35ad147dfb3d3","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync","test:watch":"vitest","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"overrides":{"vite":"^7.3.5","esbuild":"^0.28.1"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.17.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.2.6","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.38_1782640757728_0.6301711654066957","host":"s3://npm-registry-packages-npm-production"}},"5.2.39":{"name":"supply-chain-guard","version":"5.2.39","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.39","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"d5808dd64ccfa6bc9ec45d2d630fb32d3d2980e7","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.39.tgz","fileCount":201,"integrity":"sha512-5cXk/EPh1odpKx5+yBhRdL73lsOgE81f6+Vuo+guC1jtFWIO4W4yhOyKzbXk9iG1JaEDB9sJ9Dh563X+4BR7gg==","signatures":[{"sig":"MEQCIA40Kc4pHdfAetqbZvJ/iHcq0Pevqd9891CNfQwTzekfAiB8BOHrHT4tBoaVBkZAQfQIrAECFWn/88XzZv2UyAeQyw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.39","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1275311},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"6be742221c3828fd343fd2241d2a511d32546018","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync","test:watch":"vitest","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"overrides":{"vite":"^7.3.5","esbuild":"^0.28.1"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.17.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.2.6","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.39_1782649905235_0.3013552617198436","host":"s3://npm-registry-packages-npm-production"}},"5.2.40":{"name":"supply-chain-guard","version":"5.2.40","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.40","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"14757c4e9c4bc7d84ef8e221a20a41f7615475c2","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.40.tgz","fileCount":201,"integrity":"sha512-tceISZb5EcURT4eZClveJJXnqpQvtmOieuAXmXW7onAU6vidg7DgZ6tatqJVABF2lvPYpFhIqzzMzoP6arI/zw==","signatures":[{"sig":"MEYCIQCdQTC1kpPCl06AONoL6saTNgc3q2QZuwStfK9mbYaCNQIhAOg/PTTF0jaYRwGngpSRrgGxCA7o5Swu1tybSsfkLPFR","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.40","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1277179},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"7718668bb3a53dde940557bec7626b313ce9d28e","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync","test:watch":"vitest","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"overrides":{"vite":"^7.3.5","esbuild":"^0.28.1"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.17.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.2.6","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.40_1782652617031_0.2808495052503228","host":"s3://npm-registry-packages-npm-production"}},"5.2.41":{"name":"supply-chain-guard","version":"5.2.41","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.41","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"29c21deb641d512bdffcfc901c25aaca0798111d","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.41.tgz","fileCount":201,"integrity":"sha512-mtDXUIpAeoXSuyPl1kBPdYkBPg+ux7SnR+qBPBqJ8mD7/mpVTci1B38oeG4HJDXr06YUUtStAGCnGueWaNlBkA==","signatures":[{"sig":"MEUCIGcyJw7yElmvToSl/4fRjm9tbe5a9qgBOij+65L3QLCXAiEAwnTVbfVfKvMqQLyvHbnVLdZjjLsl0M/ATsOhOP/2mFQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.41","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1279880},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"980f82d81979a02d7a8f661199c5823714b849e4","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync","test:watch":"vitest","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"overrides":{"vite":"^7.3.5","esbuild":"^0.28.1"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.17.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.2.6","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.41_1782653663214_0.7535691736600303","host":"s3://npm-registry-packages-npm-production"}},"5.2.42":{"name":"supply-chain-guard","version":"5.2.42","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.42","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"b3034dfb8b10fd317e2f6f9d9438eba55ac7806d","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.42.tgz","fileCount":201,"integrity":"sha512-lSbQPim/P/mSEDdHUceo6PJ5hN39PAJrugfsIYZz+y8eyQEze5uCb0w3jfbPRSHNNPv414abRNAimweWdX94bw==","signatures":[{"sig":"MEUCIBgusJJj/R35Av6BfryjvsLCOWrbvAKkG9fVRK3V6xJ8AiEAjFbiym39wt22Qehk9hVtcHcuffjI6rSTHdSABr6dNKc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.42","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1300734},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"3eaef988de859cca189c772665c58c74028412cd","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync","test:watch":"vitest","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"overrides":{"vite":"^7.3.5","esbuild":"^0.28.1"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.17.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.2.6","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.42_1782709950801_0.2550079889139758","host":"s3://npm-registry-packages-npm-production"}},"5.2.43":{"name":"supply-chain-guard","version":"5.2.43","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.43","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"6bd31f7339f078345dd7a6108d55864d491711cd","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.43.tgz","fileCount":201,"integrity":"sha512-z+ZZjz5/aPVJRjxEiC/KVgkfkfPXlkRx/UQs/oL8J+caMQW1xBkMFsNz5ZBobLQLUeo0nSGOZvak7k603Nab+w==","signatures":[{"sig":"MEYCIQCSBevC9/zd4HF0ICZvh0CV38s3nS30vSbSg0fJnGiLkAIhAILHzH2Eq4/ZmIih+hM79tpnbI7NGB5YRcSXTPRJRn0g","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.43","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1310801},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"ea00551de8e8a95bc1bf4533acb5bf7f883e3132","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync","test:watch":"vitest","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"overrides":{"vite":"^7.3.5","esbuild":"^0.28.1"},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^13.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.2.6","typescript":"^5.7.0","@types/node":"^22.13.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.43_1782804410592_0.9529280475197781","host":"s3://npm-registry-packages-npm-production"}},"5.2.44":{"name":"supply-chain-guard","version":"5.2.44","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.44","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"2bce03ecb05959ce38d537db1ea78d821a660793","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.44.tgz","fileCount":201,"integrity":"sha512-toAeb+5nXm6CnDrW3vcwE4r2QOWE2iSglIDormfkoP9rKLcKcEYOgvR1tHZFU+mTov9qkLqh70Q1C9zcx0+ddQ==","signatures":[{"sig":"MEYCIQCTtfJnAVm67W8z4NNmWtLJMoMgGiTSEYj960c7yU9QPAIhALU9YmV2H+HKWUHHZVzkJ7ThlBj0oM1itNnljJ6uUjSt","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.44","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1311653},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"37cf622e249229d04b49f2ee89068c6e45b28adf","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync","test:watch":"vitest","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.9","typescript":"^6.0.3","@types/node":"^26.0.1"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.44_1782924760862_0.5448189235481669","host":"s3://npm-registry-packages-npm-production"}},"5.2.45":{"name":"supply-chain-guard","version":"5.2.45","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.2.45","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"bf16e55f7ae162b65a22475905d143a6e3271ab7","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.2.45.tgz","fileCount":201,"integrity":"sha512-YnTTvVV+7H2BStDeilFfzD0wXggvQ3z/c0yxrkxfqMVtYUNyL+ZBk+IfGbnPuxLEfOJjr5yTm+1LqBHnAMD/Fw==","signatures":[{"sig":"MEUCIQCAdqGs4Qo4tb00o9b9A/y+OB97z16oE5mUuXDFPah4TQIgHy1jIKDE+vrG3WQg6pnY2y8KaOJdm+dZH4khCiSoOCY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.2.45","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1246161},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"a262556c86efbcd739929a234e6a5faadb3b6e2e","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync && npm run check:handoff","test:watch":"vitest","check:handoff":"node scripts/aahp-dashboard.mjs --check","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","handoff:refresh":"node scripts/aahp-dashboard.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 170+ threat indicators. Generates CycloneDX 1.6 SBOMs, ","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.9","typescript":"^6.0.3","@types/node":"^26.0.1"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.2.45_1783007441124_0.5817297948504621","host":"s3://npm-registry-packages-npm-production"}},"5.3.0":{"name":"supply-chain-guard","version":"5.3.0","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.3.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"2ae458f429027f434ad5e2b7d9609213c21eef27","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.3.0.tgz","fileCount":214,"integrity":"sha512-qiAVNo+sQYkG6PWjixWWA0M5Jnb7hsYMmiWrEVIhgv+QEUjnEXrNUWio5mSpLZkgDQHcOIl11I/uMEUQ6OWEeA==","signatures":[{"sig":"MEUCIA6Z1JpcwPHIHlLyCXtxRfcYXILFatpTrAzVXSfT+vpvAiEAti1+2hyV/rfxx2WIppPE+r875cvrTrNmLF3JGY45Lg0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.3.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1361014},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"5f04f3e5a55c07d781b77a8d5da1e85d6fadfc19","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync && npm run check:handoff","test:watch":"vitest","check:handoff":"node scripts/aahp-dashboard.mjs --check","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","handoff:refresh":"node scripts/aahp-dashboard.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 180+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.9","typescript":"^6.0.3","@types/node":"^26.0.1"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.3.0_1783010116937_0.10078995637521837","host":"s3://npm-registry-packages-npm-production"}},"5.4.0":{"name":"supply-chain-guard","version":"5.4.0","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.4.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"5adeb96194ab8c680a0a339cc2b03d32f0f6d242","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.4.0.tgz","fileCount":230,"integrity":"sha512-VL0zR2FdkN2f1qOtIcTzn1leDdE7pvJlrByqB1tAU18zE8aKGMnyFNf2WUlvgEt3+6QD1Q8aT3mZaqeVSVd77A==","signatures":[{"sig":"MEUCIQDqt/j94/Dqr2QGWKqPFTD/erN8Pqo8DvqaGf5PsV6fBwIgNTBgei+OVkMmG7ykDhoRojKebLSybgVvACPOBpW02pY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.4.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1497749},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"b07797168ba1357a6bffc29b62243850bbd11438","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync && npm run check:handoff && npm run check:feed","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","handoff:refresh":"node scripts/aahp-dashboard.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 180+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.9","typescript":"^6.0.3","@types/node":"^26.0.1"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.4.0_1783013289309_0.41104963360999913","host":"s3://npm-registry-packages-npm-production"}},"5.4.1":{"name":"supply-chain-guard","version":"5.4.1","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.4.1","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"05348042d6810a7552f876b3adb1166ab2d23a18","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.4.1.tgz","fileCount":230,"integrity":"sha512-7CJMkedY6QLc2SF57qjgN3fH7UhjbQOSadK0JaU9WKzMdDsZY+5i4IP2rxs6F47WCTH+CwgPpybkyW0i5l5O1g==","signatures":[{"sig":"MEQCIDtTiUwo7WjAPuOYaNJJbR3B5vVHahu7XKMxsXba+X1HAiAi1Xg5+Ry2QH7BiA8f7t9TVX9iwnBkaDE5v2ZPzxg7Mg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.4.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1498107},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"4b00c731598bf9c3f4d37956433be32e56430c35","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync && npm run check:handoff && npm run check:feed","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","handoff:refresh":"node scripts/aahp-dashboard.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 180+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.9","typescript":"^6.0.3","@types/node":"^26.0.1"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.4.1_1783015235404_0.5044314232193112","host":"s3://npm-registry-packages-npm-production"}},"5.4.2":{"name":"supply-chain-guard","version":"5.4.2","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.4.2","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"4c425509c14152db54cfefec6d8a5eb269df06f4","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.4.2.tgz","fileCount":230,"integrity":"sha512-mk8rH6PnBO1THSPWYD063bpKb1QgrUV78+UVM3n12XWoaq3ctQEuf5b0Ta3Pp8BhB62KNOOcU1SEkQrwJeFUwg==","signatures":[{"sig":"MEQCIC5C0xW9AiZ49wPiYdnq7lZMIkkQaqEZYJEJkP41AAu2AiAsHr6YUOu/AhbW7I5Mp5OMz5gv965N1AEfgwe4y53JRw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.4.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1499463},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"f205eceb30b4310802011ec14d6784892d6d3270","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync && npm run check:handoff && npm run check:feed","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","handoff:refresh":"node scripts/aahp-dashboard.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 180+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.9","typescript":"^6.0.3","@types/node":"^26.0.1"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.4.2_1783018073965_0.8963434237211061","host":"s3://npm-registry-packages-npm-production"}},"5.5.0":{"name":"supply-chain-guard","version":"5.5.0","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.5.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"d9b5d32dfae05ae75de922f6cd73b6151ebcff2e","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.5.0.tgz","fileCount":230,"integrity":"sha512-1Djl6AyXbWZ5dn9wm36Xjtbb1WzN4X99JNTt0N6ve0gtbMG7Dy10kt6Pip17a5kfTwJsPCc4/3BFm/EK8OoSXA==","signatures":[{"sig":"MEUCIFqQucOVO/GTWttnqjPkOI0aoGF3hLB+MkohEOVI+sKZAiEAv9hAKQ0dGnBxfv5LJC02n1a9H+gYnhsoF3QmR0U8AqE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.5.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1511844},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"622050442cd250959ebe4ad62947bfe215f1e954","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync && npm run check:handoff && npm run check:feed","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","handoff:refresh":"node scripts/aahp-dashboard.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 180+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.9","typescript":"^6.0.3","@types/node":"^26.0.1","@vitest/coverage-v8":"^4.1.9"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.5.0_1783024340869_0.7733776171617368","host":"s3://npm-registry-packages-npm-production"}},"5.6.0":{"name":"supply-chain-guard","version":"5.6.0","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.6.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"5bcf18eac90da78edde9e02b8f426bebaa0536cd","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.6.0.tgz","fileCount":234,"integrity":"sha512-rd6otTRHayj8qUYc+75AvtqOcOpZHJP+tVe0UwslLjXExzn71m9DwnYksnKMmA/huSLggnU6kH/WFySmFaS+1g==","signatures":[{"sig":"MEUCIEYVHZF3rMfS8iu9em7+y6ZA/3W+YH3x4x4YZ5/yufmfAiEAudyQ/EoiuR5eg1SbYXhvCwTU/Bt5G9RmU++pW2FBLsw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.6.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1560154},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"e253ad97682a2f8c9dd6fa2aa39f4de737d648ec","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync && npm run check:handoff && npm run check:feed","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","handoff:refresh":"node scripts/aahp-dashboard.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 180+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.9","typescript":"^6.0.3","@types/node":"^26.0.1","@vitest/coverage-v8":"^4.1.9"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.6.0_1783030249687_0.06583455107416158","host":"s3://npm-registry-packages-npm-production"}},"5.6.1":{"name":"supply-chain-guard","version":"5.6.1","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.6.1","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"ef11c135b6a86fdf14abb861eeb20623543ca82a","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.6.1.tgz","fileCount":234,"integrity":"sha512-wuA0U6LWzTJPt52i6DQxrDWXGBPolDoR4qhk7QOvkdF2ogsglOQ4sL8P878eCnYiF5jFSgdMVY0jmdkZRK5ahg==","signatures":[{"sig":"MEUCIQDX1By9XZz6ZD+0Rc74QqOc7/UnSJRhZyftsTkv2cyEqQIgbwVeyma4hait13ljI9qG3a63Fqk7Vbt680rMpOtkdoQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.6.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1560828},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"db8a83f8408761031ffbe9510a6c5aaba5304497","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync && npm run check:handoff && npm run check:feed","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","handoff:refresh":"node scripts/aahp-dashboard.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 180+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.9","typescript":"^6.0.3","@types/node":"^26.0.1","@vitest/coverage-v8":"^4.1.9"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.6.1_1783062771641_0.9272328842615418","host":"s3://npm-registry-packages-npm-production"}},"5.6.2":{"name":"supply-chain-guard","version":"5.6.2","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.6.2","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"e7ca3aab59e01db07f2dc328cd9c3e7f161dbb56","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.6.2.tgz","fileCount":234,"integrity":"sha512-TLrG/EuT/DLQr3slhXFtmyQpoUICJRjFfIfOekfbkcdp7/Lik6SQQ7BclQoJt6vpaSZsF78SADSIksE796DaxQ==","signatures":[{"sig":"MEYCIQDqOdR8EsTW5c6wpKjXf+nDAKm6syAIZl499u6q4MGnGgIhAMNMXLT9hYGnmutFbfkr8xjCIWAnxQL51bVFfd66vL4E","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.6.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1568902},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"04e8f8d2de15b02985a8f9f92f57126898f35764","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync && npm run check:handoff && npm run check:feed","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","handoff:refresh":"node scripts/aahp-dashboard.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 180+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.9","typescript":"^6.0.3","@types/node":"^26.0.1","@vitest/coverage-v8":"^4.1.9"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.6.2_1783142075959_0.5564439551583247","host":"s3://npm-registry-packages-npm-production"}},"5.6.3":{"name":"supply-chain-guard","version":"5.6.3","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.6.3","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"4c5d9caf380b16af05f154119ca0519a1289dc67","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.6.3.tgz","fileCount":234,"integrity":"sha512-+erERS4hVzdOIthz3PLcS6bMaV0lkOQmEErCkbnIAdccPyNpUlzAgH+3XekLs/puzuEP1/o2GEwabARvm4OoxQ==","signatures":[{"sig":"MEUCIQCZKm1pmhxXh20up53D8g+V5sNfzkLBsP2G5lVubV2MPwIgIygmdrSAuPmFiNFJV+XOW49q5Mw/4WyobKiwp9256qw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.6.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1571287},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"a548c307f956bde826e90fc6fd1f9bdd9573bd3e","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync && npm run check:handoff && npm run check:feed","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","handoff:refresh":"node scripts/aahp-dashboard.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 180+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.9","typescript":"^6.0.3","@types/node":"^26.0.1","@vitest/coverage-v8":"^4.1.9"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.6.3_1783427438862_0.5274181062714127","host":"s3://npm-registry-packages-npm-production"}},"5.7.0":{"name":"supply-chain-guard","version":"5.7.0","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.7.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"b1c177194ebbfe025acc43ca12a3205e30a16bc2","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.7.0.tgz","fileCount":242,"integrity":"sha512-Twjqp7iS/mRa5l6hlPUlN2nBwduPFl4r5WsVjo2TkWvLqPHp9Mc6BQfBh62GwsBjtSH7mqPOIqy34u50kgU2eg==","signatures":[{"sig":"MEUCIQDwtL1pfQH10GwUqlMMmsrBV9COOjTwko4r4Rq+JM6omwIgOIM/yUNux4hfftWJn2Daj9NQXQHelN7Aymu26e6ByqY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.7.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1641068},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"b0aa7254a1acef49d80b6341319d0d4e231ab65e","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync && npm run check:handoff && npm run check:feed","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","handoff:refresh":"node scripts/aahp-dashboard.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 180+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.9","typescript":"^6.0.3","@types/node":"^26.0.1","@vitest/coverage-v8":"^4.1.9"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.7.0_1783438561338_0.13307360696869153","host":"s3://npm-registry-packages-npm-production"}},"5.8.0":{"name":"supply-chain-guard","version":"5.8.0","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.8.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"db69bccaecced07db062cf15af51681fcce1461e","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.8.0.tgz","fileCount":246,"integrity":"sha512-7EixbbdZThVQz+ar6P2lsjZKUnissI+58+Ae9ddP1HhT3zDT00eJTrbiP1uQl7BJiKSZb5d5PEj7Lgbj1CVDsw==","signatures":[{"sig":"MEUCIQC9zRoyA35A9SkazI5qqyg//THDYwmU2JSD+VjR1mgcCgIgYeZ1Sa1KVMij3nPdiqi1wkJftF/3lpyTWDsDytBdUDQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.8.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1656709},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"4d93f1092eeafa73a36ab8790e77d5edd53bd0d1","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync && npm run check:handoff && npm run check:feed","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","handoff:refresh":"node scripts/aahp-dashboard.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 180+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.9","typescript":"^6.0.3","@types/node":"^26.0.1","@vitest/coverage-v8":"^4.1.9"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.8.0_1783446726064_0.6010673008761951","host":"s3://npm-registry-packages-npm-production"}},"5.9.0":{"name":"supply-chain-guard","version":"5.9.0","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.9.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"56f225f3c359cff4ef39e2a05d3595bf1cb42397","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.9.0.tgz","fileCount":246,"integrity":"sha512-OvCEPP0g1DG8QV7vpzO81uqsKldsKXDRdaB7sRLY3iIojx1q0OJ+fipUbccb71h+u5G8Pqb1PP02zeNoxRUGFQ==","signatures":[{"sig":"MEYCIQDT/wkQLLUIA74Kt2V++yWId0FcwCsTwg//Cc8HScPSEgIhAPaavR/3F1u8RJqNxmyta+TyVIAbr+bxP8KTiQjv5ETr","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.9.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1670160},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"9ca57a408190c2fb714c7224b9a5dd725ac6f615","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync && npm run check:handoff && npm run check:feed","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","handoff:refresh":"node scripts/aahp-dashboard.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 180+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.9","typescript":"^6.0.3","@types/node":"^26.0.1","@vitest/coverage-v8":"^4.1.9"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.9.0_1783449523889_0.697205650895997","host":"s3://npm-registry-packages-npm-production"}},"5.10.0":{"name":"supply-chain-guard","version":"5.10.0","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.10.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"e4bd59b6538591e55e82c340ce8087b153a01f30","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.10.0.tgz","fileCount":250,"integrity":"sha512-p5UTloW5mUJtqgc7+ilOHgtzgcIGiquxJPHMr4vhG0W24OScmHqnIVfbf8eZLfXX84wKtTkTx14lSiLaxSEziQ==","signatures":[{"sig":"MEYCIQDLbiuffSg7HVIR6W5fMz9yJ3CTiNx+WanLtLBpzgk+BgIhALEFfUPCL6FiK6OhEGQerH5HN2VMmd1d8SRdZhVQ7sRH","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.10.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1707267},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"8c3eaed1148c393da954ab1af917442fd419e8cd","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync && npm run check:handoff && npm run check:feed","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","handoff:refresh":"node scripts/aahp-dashboard.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 180+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.9","typescript":"^6.0.3","@types/node":"^26.0.1","@vitest/coverage-v8":"^4.1.9"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.10.0_1783527454106_0.22836759692760888","host":"s3://npm-registry-packages-npm-production"}},"5.11.1":{"name":"supply-chain-guard","version":"5.11.1","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.11.1","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"dc963542eb949780371fae1a8618cf2f5d7597c6","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.11.1.tgz","fileCount":250,"integrity":"sha512-PEABoEM3VUP9j/3nb3VXpuJa4P1+KOelbERmPteVD5ca7LKo83HY91EhDOXPk6OuP3Az2uAf5O7gi/kzpD0KXw==","signatures":[{"sig":"MEYCIQCj1eFGH9BDSq4qI/O5puYJ+SQ4TEVFngJm512a0KDGJgIhAMWy+lWRC1kiFpa9rgKQ1EMNMxbbKby4xhfhakoKOdek","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.11.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1717837},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"aa685e96e1c23621940e89e5d89553d381e322b1","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync && npm run check:handoff && npm run check:feed","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","handoff:refresh":"node scripts/aahp-dashboard.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 180+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.9","typescript":"^6.0.3","@types/node":"^26.0.1","@vitest/coverage-v8":"^4.1.9"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.11.1_1783617038909_0.5098366072623628","host":"s3://npm-registry-packages-npm-production"}},"5.12.0":{"name":"supply-chain-guard","version":"5.12.0","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.12.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"e00a50baa7aade03ba467024ce1b5f2fd3702778","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.12.0.tgz","fileCount":254,"integrity":"sha512-gueZT9DPEoYjnUX2Q1thLHKK8zeGk10SfRg/qvj1pzv7f2UJZaKI5hgHGFjLxbL1FZOmHwjguLm94stC6rDLnw==","signatures":[{"sig":"MEUCIFNN6FXuO7sqMbpVcExkeginUc/yNUxXiVxbKENFdGGDAiEA5Sxy2s34NPrlsV0dE4vhxTEwqyGFHXUXxZPnxlq2MAI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.12.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1741497},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"89ad038343dbd1f28f92593bfb85193fa7f823a2","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync && npm run check:handoff && npm run check:feed","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","handoff:refresh":"node scripts/aahp-dashboard.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 180+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^6.0.3","@types/node":"^26.0.1","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.12.0_1783782599344_0.5255569567246572","host":"s3://npm-registry-packages-npm-production"}},"5.12.1":{"name":"supply-chain-guard","version":"5.12.1","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.12.1","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"24266942d12bda6e5571796aa234f77abac4687f","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.12.1.tgz","fileCount":254,"integrity":"sha512-3DyzGLq6QdmQfw1tGuFrTVWdnL2Ms4S5B7YLRNLt+0Je1nnFgFUjIb5RXrDHLtJwMk1alrotEfagM+THLF0NJw==","signatures":[{"sig":"MEUCIQCM6C6qkplsHM58cAFjQ/aFn+Vv84cDcGikiR0lQGggdgIgeM9fZeFytmhCDwV4VQZ9BQ4Xw3WeaYelZp3zKkeqs8s=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.12.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1742180},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"c4865d37727b23b79ea3caacacb47dd4bd511cc0","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync && npm run check:handoff && npm run check:feed","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","handoff:refresh":"node scripts/aahp-dashboard.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 180+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^6.0.3","@types/node":"^26.0.1","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.12.1_1783835985596_0.46761896234481326","host":"s3://npm-registry-packages-npm-production"}},"5.12.2":{"name":"supply-chain-guard","version":"5.12.2","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.12.2","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"54aebf58cd19699352b450ab2cb8ca2f111399df","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.12.2.tgz","fileCount":254,"integrity":"sha512-cJt1fYF71jZx/5Ks3Dl/TgU5UIdppFN+8Y0gznGc5YjD9dHKNpqA+wjkj15R5jzaoMDSc8qhehofZec3HDPuYQ==","signatures":[{"sig":"MEYCIQDoM2UcIRuhfa/EvJfKPVcfDrOzKtFLyVKoYoV2Cnj9AgIhAMubHqWpFCA0tyGUlIUJLz48t0UBu3Xt8IroLfeHikm+","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.12.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1758834},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"c549b63261db915ec889c0cb2d991e8467a7cf92","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync && npm run check:handoff && npm run check:feed","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","handoff:refresh":"node scripts/aahp-dashboard.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 180+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^6.0.3","@types/node":"^26.0.1","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.12.2_1783925556161_0.3510161884420675","host":"s3://npm-registry-packages-npm-production"}},"5.12.3":{"name":"supply-chain-guard","version":"5.12.3","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.12.3","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"9e402e3bdbe2a2548066130139c7d34ff8b87055","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.12.3.tgz","fileCount":254,"integrity":"sha512-GmE2Z6NYpPqNAXd9+4+F8Ab1XM7XL7wfloFYhHvzhieiijMKj/9wjlgI+yhNh4H3FW0pcwLkqMR1uDhmIXxsbA==","signatures":[{"sig":"MEQCIBxtFmuveH8IWk3dangp91Ftr2N63M/Rg3Q3uvHMxyU0AiAykmOkh0kzCYJ2r7K1AOlyAPf00m6mXlOApn49T+nL4w==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.12.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1764439},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"7796e387355b43e145147538b67967976cd4d112","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync && npm run check:handoff && npm run check:feed","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","handoff:refresh":"node scripts/aahp-dashboard.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 180+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^6.0.3","@types/node":"^26.0.1","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.12.3_1784199182498_0.4267301053230508","host":"s3://npm-registry-packages-npm-production"}},"5.12.4":{"name":"supply-chain-guard","version":"5.12.4","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.12.4","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"c3a5f1eeea1a0dba179fc8d32dcfb88bea3e308e","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.12.4.tgz","fileCount":254,"integrity":"sha512-fZ04X4o/+LkROXt+R9bWEY+aJu75ZQQ7QyqNVuCGTVPf9Hdp2ckNqy4Js/oyqq0uy3mB7E/E8JmGC/BVzEKXew==","signatures":[{"sig":"MEUCIEHZh/n9FFmYNqtcJtvBjH2yqX08MfFhIyj2kYhnr/B5AiEAxIFvAsZiDxCSvx+fWur9UZ/UoQ/f/IcsZ6RaVB70b24=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.12.4","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1779860},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"315303b7efa9b63f7347a003cd606b7facc9b6eb","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync && npm run check:handoff && npm run check:feed","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","handoff:refresh":"node scripts/aahp-dashboard.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 180+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.12.4_1784270620031_0.6253765952422492","host":"s3://npm-registry-packages-npm-production"}},"5.13.0":{"name":"supply-chain-guard","version":"5.13.0","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.13.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"6889533a1306382f533c5e8e9a4d440a0a8faae7","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.13.0.tgz","fileCount":258,"integrity":"sha512-XCkL6c6dbkjLqKmO3jUBhASZI2GlhdewFbqIxcye3YL77A5x+s+vsxwNnHnXRMMO5MBu96dvNPlD095YXolRLA==","signatures":[{"sig":"MEUCIQDUO3tAQszwJUupUgjnT6wFptrSLxjki4LLxWaSueUPTgIgM9jXHjg0kA7loI987SnoxNEZfngzmEPnnU+y6bZn2tM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.13.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1815273},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"89ce172e80c3f66709bb422b1a26f9aca2763675","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync && npm run check:handoff && npm run check:feed","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","handoff:refresh":"node scripts/aahp-dashboard.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 180+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.13.0_1784271765515_0.03083368530314745","host":"s3://npm-registry-packages-npm-production"}},"5.14.0":{"name":"supply-chain-guard","version":"5.14.0","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.14.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"8ab2d7d5c0bd14689f889296e9ae1a3b55f2547a","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.14.0.tgz","fileCount":258,"integrity":"sha512-19C/93H+oDu+DjkRi5iI2M51CK+o/RPyW6z8H24rTqGRf/p4VUWiR6kq0O00vpXZ/hKrdG9RXNkbrYdBMnuj7g==","signatures":[{"sig":"MEUCIQD7opdESMdOzp1CnIFoxkrLV6WAJ9qKZOrBysNymrXXIgIgURFiPkOQSn9bqyTx79Gl6GkSd7ToBedYkJ9xxtNEUHY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.14.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1842782},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"8fdd859b98bb25f07fdd4db9d2b5571d85f4586a","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync && npm run check:handoff && npm run check:feed","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","handoff:refresh":"node scripts/aahp-dashboard.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 180+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.14.0_1784272684695_0.336853339052396","host":"s3://npm-registry-packages-npm-production"}},"5.15.0":{"name":"supply-chain-guard","version":"5.15.0","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.15.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"caee2ea6dc99369241277eb5708a04347fc6a515","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.15.0.tgz","fileCount":258,"integrity":"sha512-kw6FozOse4Qd9EpqOGST5x6E9BadmvYiuH0N2msVdJUxF1AUdgwBbYCrsn5JwfhEYii/ZAtZjpFlW3ZRk7+8IQ==","signatures":[{"sig":"MEYCIQDsZ1LYJ6Yu9/CR1Df/KeMXvdRy70hB3NsiA8qlEJnjlQIhAJFaYBqA8KfNWrkoNkgHkstcm8ql6PjU/qfqcD9gdr+4","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.15.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1857977},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"819dfc510640aad3a6a96b21e7831f09b8d8303d","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync && npm run check:handoff && npm run check:feed","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","handoff:refresh":"node scripts/aahp-dashboard.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 180+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.15.0_1784273770004_0.966066287753202","host":"s3://npm-registry-packages-npm-production"}},"5.16.0":{"name":"supply-chain-guard","version":"5.16.0","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.16.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"582dd23e88fde28ec172c6906716313fa902826f","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.16.0.tgz","fileCount":258,"integrity":"sha512-8++ux3O1rZB8NiypCcIHL92qqTt2zrcuxK3gCnDFqazFAnDaeGY+FyfUIJVc192iooL0gDJzC3+FPIwBlB/GCA==","signatures":[{"sig":"MEQCIG3xhVqZHx1GcSpKcsqG0NhbggdcYcIDhiyCSjMIVCqXAiAp7CHd8b8BPywzvXkYo1eOjIbCKRujiG3wFy2xBa8eKg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.16.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1873949},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"5bfb169cad48058f24b610f140230a323f310f43","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync && npm run check:handoff && npm run check:feed","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","handoff:refresh":"node scripts/aahp-dashboard.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 180+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.16.0_1784275231287_0.12563267270299905","host":"s3://npm-registry-packages-npm-production"}},"5.17.0":{"name":"supply-chain-guard","version":"5.17.0","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.17.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"17b9f757737fa5c3e5f4046685090827ca6369c8","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.17.0.tgz","fileCount":262,"integrity":"sha512-GQQVd3oFaI9tANLQC5YKjyWBTkG+SbJ7pY1+ItdkJxzW3pP/LLczUp227+KNeNmqKiIf2OpTDbfSPo8mz+PINg==","signatures":[{"sig":"MEUCIQC1V3387lzsyD0F8lny4zAwSlqNt00eR0+6oH/L10CTXAIgXcpeLFUhF6FwjjBDoPJ3+ZQDiDEIoIwM7/oGLcoUu20=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.17.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1888964},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"3e148d870f1f632c2e872be3398bb6a9926887b4","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync && npm run check:handoff && npm run check:feed","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","handoff:refresh":"node scripts/aahp-dashboard.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 180+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.17.0_1784275869289_0.15189461822172023","host":"s3://npm-registry-packages-npm-production"}},"5.17.1":{"name":"supply-chain-guard","version":"5.17.1","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.17.1","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"cb4a3cb32be2f5d3ba336bb6c84953ed1f5ccf91","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.17.1.tgz","fileCount":262,"integrity":"sha512-hd/V7l+Nt+L4yn7c9BW3939eIwY7nyAT8NqHaZzWE3wcnMeyZGDFzSFrtn7r/7mcXqcmV/G85nFfEdW1BCv2gw==","signatures":[{"sig":"MEUCIQDoWlC2mrLjno84ze9ZJLeI2L3I5CYEhcLPWTVerQYczgIgEy0aQ9fyCdeYoGGDa5QN5x9da/eahWsDS9C92o/SZkU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.17.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1889052},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"25a495250ec44353c79806afcec1954a821cec40","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync && npm run check:handoff && npm run check:feed","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","handoff:refresh":"node scripts/aahp-dashboard.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 180+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.17.1_1784276662160_0.458920790691713","host":"s3://npm-registry-packages-npm-production"}},"5.17.2":{"name":"supply-chain-guard","version":"5.17.2","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.17.2","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"c72a4a6a5e50f7ad40c731094ecc70da59934cf5","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.17.2.tgz","fileCount":262,"integrity":"sha512-GvdLHDW1Q4OqocWm9orfOxwMupeF6gKUk9z5LJ6WkoExxQvlqmKWmsXBwUmGj4+KJx+U6W2BABRqEbsmA+k4Ew==","signatures":[{"sig":"MEQCIHJEExy35mpkK7oS0ansJ+g6M6/TR81Byq55QCV92LvaAiAabn9gTiBKfObs+x7CrB9005odZLnnzHhNfZOytIs/Cw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.17.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1891633},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"a1ae6293cad77c379d39e466850c6fd8d4dd453c","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync && npm run check:handoff && npm run check:feed","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","handoff:refresh":"node scripts/aahp-dashboard.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 180+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.17.2_1784278037769_0.24971715706340292","host":"s3://npm-registry-packages-npm-production"}},"5.17.3":{"name":"supply-chain-guard","version":"5.17.3","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.17.3","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"275d7049645e4262543ed359bb979764737d7276","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.17.3.tgz","fileCount":262,"integrity":"sha512-6StweQ6Z59x0NJnNL1amhjjcrWpNoOWrci2WSKOHFSB7FqvCtJ4rhUu3tZt+XZDtBypDwA21DcEhvxuMpX6CBg==","signatures":[{"sig":"MEYCIQDllYj9I5KtbRKFU/JOl3wOQ7q7Lng0H8N5MFcaxBSclwIhAOw81jQ5Wj1MeM0DeoWyxUYVAp2SL1MJ5iJxpZF8XuDT","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.17.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1895603},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"0035aabf64e7bd69a8899ef467aa4854081acdab","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:changelog && npm run check:version-sync && npm run check:handoff && npm run check:feed","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","handoff:refresh":"node scripts/aahp-dashboard.mjs","check:version-sync":"node scripts/check-version-sync.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 180+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.17.3_1784353002499_0.7154266927742559","host":"s3://npm-registry-packages-npm-production"}},"5.17.4":{"name":"supply-chain-guard","version":"5.17.4","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.17.4","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"909ab8469eda5fdaa566c1ecd552205b7ae6498e","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.17.4.tgz","fileCount":262,"integrity":"sha512-dKuQGzhtoHIey67R2g0Ge2qCh1TwDeuL5aRfuZIkGVmio/aOspSuwMrHS48/a60EMUWqnVbIrs8G4H7/mp1IgQ==","signatures":[{"sig":"MEUCIAMrHwPC5mZQ8jcKDSQFC6SFP8nHbS5ImEvB3eNszFy3AiEA0f5PRz8yfPyt19ht44WBuVHzpzsgOiH/S9+AGoEReh0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.17.4","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1895966},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"7cdb98bb09d40ca1f7849a5e0a94164e86b52eb6","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:changelog && npm run check:changelog-format && npm run check:version-sync && npm run check:handoff && npm run check:feed && npm run check:claims","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","check:claims":"node scripts/check-claims.mjs","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","check:changelog":"node scripts/check-changelog.mjs","handoff:refresh":"node scripts/aahp-dashboard.mjs","check:version-sync":"node scripts/check-version-sync.mjs","check:changelog-format":"node scripts/check-changelog-format.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.17.4_1784384291675_0.9649187556507819","host":"s3://npm-registry-packages-npm-production"}},"5.17.5":{"name":"supply-chain-guard","version":"5.17.5","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.17.5","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"b1eae6cac99acd3ddbba5029207dd06295fa68cb","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.17.5.tgz","fileCount":262,"integrity":"sha512-Q6LiIMNYnIakoOE202WYv9aCFc5V1GhUQwa5i76sut7ix1lqEOlOvo68Fjg1QXEKSC55zt26cAp0pOCgYc5dmA==","signatures":[{"sig":"MEUCICigcvKqjl31xalLaVxKUcBqPz6Km1Cj+rPlD1j0vTAkAiEAsc9xfMiQkKZvLh7CrPTwc/xps0q9AZvQcyeg/weFPh0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.17.5","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1898379},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"cdb489255917a05827eacfb9936e5dd14bf29243","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/aahp-dashboard.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1","@elvatis_com/aahp":"3.8.0","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.17.5_1784441999821_0.33279586628906954","host":"s3://npm-registry-packages-npm-production"}},"5.17.6":{"name":"supply-chain-guard","version":"5.17.6","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.17.6","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"ab4026afec7fea1f89fec6f855699b8b1766a133","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.17.6.tgz","fileCount":262,"integrity":"sha512-QJ89JDytTNg+3C+RNqbOgRtGk7r+e86RFfLGDdF7981v56jvcSSGqP8B3/VfGlJ84LyIU+UpOYb4XhfH6AxyLw==","signatures":[{"sig":"MEUCIQCh1sLb30HYYsxnDC70EALzyxI2V1G37Z+rUGshc7ZgLAIgHH5qYOuQvqBAYfwKgp6RP7K7yT0K3oIFqRAQFxhirpE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.17.6","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1904926},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"5560a5865002e7b4acd57a0932d242f6569f6eea","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/aahp-dashboard.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1","@elvatis_com/aahp":"3.8.1","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.17.6_1784545792377_0.7099153856825049","host":"s3://npm-registry-packages-npm-production"}},"5.17.7":{"name":"supply-chain-guard","version":"5.17.7","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.17.7","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"cb8b31237d6f05d44b90b0d9b2be02fadc98dd02","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.17.7.tgz","fileCount":262,"integrity":"sha512-Cb1pwIQcB4ALces9hXAdQgPscMAlGCL4Z2HlyMvjIbDGPEgqWDZfMqxJO5kKbqX7NuYvx3xm8a1brJ9zgKC0rg==","signatures":[{"sig":"MEUCIHKkq71yiSozSKV59ewrQfj7bPxKmP8rSZ/jQ/fW7sr0AiEApQSmANJL/72ijF5d+AL+AakPCVY08wgIcfODGQsCR2s=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.17.7","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1906286},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"0c7cd61806c71fdfd68b3bd4d77e02bb105191a7","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/aahp-dashboard.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1","@elvatis_com/aahp":"3.8.1","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.17.7_1784647829108_0.5511567144769651","host":"s3://npm-registry-packages-npm-production"}},"5.17.8":{"name":"supply-chain-guard","version":"5.17.8","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.17.8","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"c73b56f3529862d4a5e3ad65d911ed465d79fa96","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.17.8.tgz","fileCount":262,"integrity":"sha512-VLK5tNaBjblmB/g7CfGsIQ8fYGsEiYJb+MFTf93i6Y01aPI/3K5N1B3B+iqqXh0YW/+7pg/eZqXQMIwJXUo4qw==","signatures":[{"sig":"MEYCIQDVkY4GkVF60q7ZGkWZBnT329cfvitMAMC8vAxVo2Dz3QIhALXNOKqkDUExdAWnhl7c7ZIusiZjJ69+BSzXopgF1M4r","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.17.8","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1921359},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"d1a670fc21b8e213e774819aa9a6d7643c729e84","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/aahp-dashboard.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1","@elvatis_com/aahp":"3.8.1","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.17.8_1784913319789_0.23173058340210795","host":"s3://npm-registry-packages-npm-production"}},"5.17.9":{"name":"supply-chain-guard","version":"5.17.9","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.17.9","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"c9b560482da262aaed3fce0ceda3bc940ffc0b23","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.17.9.tgz","fileCount":262,"integrity":"sha512-2eE8gXp0kdufgii+nKpmVvdOBRY0XttsEJ9RzSAxbVYJEyM/WmjQDdC/6sHUqVX39ipWfcDy/4SpoBfrQ+c9MQ==","signatures":[{"sig":"MEYCIQC20pu0CdsoILGayJpe0zXhTK0V3vnDKQXRDO6oOmoDKAIhAMyIePpaDhejZGi5P39oNJ0UQbE0jbhcNTdMzo0/COeA","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.17.9","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1930918},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"52a87b3799575d353d52deade02380fa3eb9aa85","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/aahp-dashboard.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1","@elvatis_com/aahp":"3.8.1","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.17.9_1784956332031_0.5591946754111001","host":"s3://npm-registry-packages-npm-production"}},"5.17.10":{"name":"supply-chain-guard","version":"5.17.10","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.17.10","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"3ad8f7722cd9c4fe4a18a26df0ad928be0ecdfb5","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.17.10.tgz","fileCount":262,"integrity":"sha512-jsO+YeG0Z58V6d1o5Hdfo8+Sseb+mrto+j4AECuligYoibFnYLrlWH3SGYwk6EtvRBK09tb2xEzkwNj0fXADvQ==","signatures":[{"sig":"MEQCIG+3A1lC4BWzsMCHt+wtv+kueHxlsF+HCDO1HmeEYRRKAiAKXo+VC0jvxGWh8OKV//4tGEeWHXo4mwYEFS3I2V/qoQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.17.10","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1967702},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"af7c110e6054af4f53f46c069cc80f97956791dc","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/aahp-dashboard.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1","@elvatis_com/aahp":"3.8.1","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.17.10_1784965909013_0.6144191119147033","host":"s3://npm-registry-packages-npm-production"}},"5.18.0":{"name":"supply-chain-guard","version":"5.18.0","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.18.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"3ce00afd9310cc20397cc2baf27c6c3694718f09","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.18.0.tgz","fileCount":266,"integrity":"sha512-RM7b1e1EU3YALAzZDKa04XE6MUKV+So8mz5V/rWV3Revs38E3y2MW3g1nlsGHpTfjFbdIWvMTTVbPrTSfOjFRw==","signatures":[{"sig":"MEQCIFD03fKtp7l/RQPTbjPJeUPxqRRDbALl3N/sxV35+C1TAiAyNBOrIhcHIZx6Vz2eh1vInqFxCxyfmz96cfe4XlHRYQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.18.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2152743},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"c735a24182d8150d4c374e66f639b0e9c6e0b565","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/aahp-dashboard.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1","@elvatis_com/aahp":"3.8.1","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.18.0_1785003765862_0.6074258446942649","host":"s3://npm-registry-packages-npm-production"}},"5.18.1":{"name":"supply-chain-guard","version":"5.18.1","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.18.1","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"6fa7da5362cad36ec6c78ed0a42640dabcd42ccd","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.18.1.tgz","fileCount":270,"integrity":"sha512-o4eOXlel+rfh7yGlBCkZ8V4QNNRezY5DnAHIqWOHOywLaQAF+cuzdIASInx5HBSB8vtlYw5CnGUVVhUliQXxyA==","signatures":[{"sig":"MEUCIGzfhmnyXx67wK9IfYhXBpo8Lqy7nUrO7yZ0N9VO47ZqAiEArSL1eyDa844/HrfAcZ9HPmzTiVEzwoF1R8zu16zcWF4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.18.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2158928},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"ff1adb8fe29124b2703f2ddafa3faba74ffaa8e9","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/aahp-dashboard.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1","@elvatis_com/aahp":"3.8.1","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.18.1_1785005904952_0.8687835671557167","host":"s3://npm-registry-packages-npm-production"}},"5.18.2":{"name":"supply-chain-guard","version":"5.18.2","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.18.2","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"8f4e10f8fac8e5e413e459ef8c2d63f8d2014959","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.18.2.tgz","fileCount":270,"integrity":"sha512-v2/rPJadL+9ydGgbh/esR1RmJweKtsQfh9UdhDSkG3Hj4m8xEk2HLBu5NSS4U5iWRMtCnMrMLoHDJsxCk/RfpA==","signatures":[{"sig":"MEQCIFZNOgD91s+3ZQ9fxdoEECcme4t6eX7qD7NkMM0ICUlyAiAzFdiisevZ0VjUp9RI/91E9Zs0S54fNjFpX8M0YdkK0w==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.18.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2233927},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"67de77e47c7c3cff3e7750f28003c93f30ba630a","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/aahp-dashboard.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1","@elvatis_com/aahp":"3.8.1","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.18.2_1785052910187_0.3283002031638713","host":"s3://npm-registry-packages-npm-production"}},"5.19.0":{"name":"supply-chain-guard","version":"5.19.0","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.19.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"a65fcd0138c8632095190bf539c433c9e9841ae8","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.19.0.tgz","fileCount":270,"integrity":"sha512-j9Lrw7XQvWKHQdztvp0LBKU6YpOUSYy48eTGU0rsPDBr5vRYKL8JKIwDhGGauV+tP8Ol9w9m2x+dUUoBs4H4zA==","signatures":[{"sig":"MEYCIQDNsNDTQ8PIh0dGzoDrSanWco73drJfaFTjCYF6rETR1AIhAM6Xlw26CDDm2+e2nD1KpjElKqCyL5MpqcgZIWOCawZP","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.19.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2233927},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"22765e58fcbcce08e744328be9d3df86f31c6775","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/aahp-dashboard.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1","@elvatis_com/aahp":"3.8.1","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.19.0_1785058835638_0.871874883687525","host":"s3://npm-registry-packages-npm-production"}},"5.20.0":{"name":"supply-chain-guard","version":"5.20.0","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.20.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"1816ccfe4fed02b1232cba206aa21fe21ee2ea3a","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.20.0.tgz","fileCount":270,"integrity":"sha512-6HcIStT/qBy0kcu0t7SFxxCx/r5/znCIOZhDLfghv6PbejoRbNhyfNhNblV6dLE9YhRvfzmf2vpId9jK9UNlnQ==","signatures":[{"sig":"MEQCIEp8UnyDD3JyrsK1IKYTlxt1JSrFhKNN+DUsXt3rgeD6AiBuOncBsJ6VVbMvtrdTQmhiygUQ3hy3s6my6TGQw3kkCQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.20.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2336262},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"b382ba92a62a751faf0a2179a7c143b580835648","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/aahp-dashboard.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1","@elvatis_com/aahp":"3.8.1","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.20.0_1785147637925_0.22199579502732725","host":"s3://npm-registry-packages-npm-production"}},"5.20.1":{"name":"supply-chain-guard","version":"5.20.1","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.20.1","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"349c47aeb91410fad8a06a54ea1238a6ba139ae3","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.20.1.tgz","fileCount":270,"integrity":"sha512-s6eyooG8WioPibRB1iHPDUsTWyFm+bMnJq11Sz5M6IFG1gU1hhKj4Z+14QQQkmTXIrDUBql0VcvoC3BQkzcD9w==","signatures":[{"sig":"MEQCIBdmz/RwzFEpekbiYfgW6wwR32jJTclCdQRa08i5G8uyAiASF4xUcBP5fVaJWaqB6oi55Vc2j2kawMgldLORUUFuYA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.20.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2418341},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"55f4e2ef8a28b88564b9a67b63b16b67a203232a","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/aahp-dashboard.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1","@elvatis_com/aahp":"3.8.1","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.20.1_1785222147363_0.2820056212163584","host":"s3://npm-registry-packages-npm-production"}},"5.20.2":{"name":"supply-chain-guard","version":"5.20.2","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.20.2","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"62f406c7cd9afa555254b249da14d8db656ab71f","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.20.2.tgz","fileCount":270,"integrity":"sha512-N8RGIcwAF5Un6dHVaafLOOtl7cEMK8li+6unzxByq9r9mRLqfh06lruAsd26XaW59d+J5K4BqAu9UoJSRCgZ6w==","signatures":[{"sig":"MEQCICNUVqmoU+yZr2pwIl9uVXmNHwOXK6R7OCHz6vspGRkGAiBzOvxDisH4bznELXs8P8WyIZBXhwus4VOHb0H2GQjjXQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.20.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2419067},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"2f254695ebb057f81e5553507c026c69ddc3857c","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/aahp-dashboard.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1","@elvatis_com/aahp":"3.9.0","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.20.2_1785224882551_0.21422568527107266","host":"s3://npm-registry-packages-npm-production"}},"5.21.0":{"name":"supply-chain-guard","version":"5.21.0","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.21.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"83388a110285a208f532aa84c5b4a9706d011c2a","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.21.0.tgz","fileCount":270,"integrity":"sha512-/kZNOpaPtXQ+DRrmuU9tS/2u09aYvOhQv/O6DWhEMDPqOMBEzWRV03Jq5Htpu43jTbvmuZtlnajqQXCipioYWQ==","signatures":[{"sig":"MEYCIQDmED0K3CJIM/ldIkVZuOy7/Gwqt8vkriF+3gZjUonLHAIhANeYQ0ze0XWdyuWI9RfIc7Eka2xciBv3r3VOiXpWgprI","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.21.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2537932},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"f7ed9fd618cbbae2a1e0f72654e40de9a53384ce","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/aahp-dashboard.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1","@elvatis_com/aahp":"3.9.0","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.21.0_1785324409405_0.7792089110277769","host":"s3://npm-registry-packages-npm-production"}},"5.22.0":{"name":"supply-chain-guard","version":"5.22.0","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.22.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"7ac378a530eba1cbf02635de665447c54ace9917","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.22.0.tgz","fileCount":270,"integrity":"sha512-dHBVz0bX+i1/LfYQRFNzRIkasFqJCm+r67OhxG+D7ZBJZZwUmUFQBOaCwuKY9F9hGAJ3A3aa/oVRJepp5SPslw==","signatures":[{"sig":"MEYCIQC3+27nErby4CXKy2TLJ9wtpVgDSETOcrebNN2Aswq0IgIhAK3LL37xq75GY/V43W5VBfMrkT+uGPRwAsDRiVaXr2sE","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.22.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2559005},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"b65d36afc97a136886eb87ec25bb59fe1e01ec2f","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/aahp-dashboard.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1","@elvatis_com/aahp":"3.9.0","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.22.0_1785332610230_0.012959330481048692","host":"s3://npm-registry-packages-npm-production"}},"5.23.0":{"name":"supply-chain-guard","version":"5.23.0","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.23.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"4b12730918b438671fc2db4e33cfbfa70e932799","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.23.0.tgz","fileCount":270,"integrity":"sha512-X5tq9Oq5t/g+vuR9KL2QYsKDk8BpUPpX4eSVRdjRchb+yv1wO9WK0uNP0DmD/qatERZk89Wiho7WnMZnZ2C5Gg==","signatures":[{"sig":"MEUCIQDf5JjdPHsYqBjopkPiE6Tl1R6LZq4rx+WqALPwq0M+0QIgfn+dPrFdO6NuSH2t5Tbuc73FA2WO2/M+jXhsdwJyqBo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.23.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2564210},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"fc323800b7a6e10c6ad42bd15118df2a645bcc4a","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/aahp-dashboard.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1","@elvatis_com/aahp":"3.9.0","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.23.0_1785334554166_0.589963166317659","host":"s3://npm-registry-packages-npm-production"}},"5.23.1":{"name":"supply-chain-guard","version":"5.23.1","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.23.1","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"6a666df5803f13ac1d2104a101711e848f1494cb","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.23.1.tgz","fileCount":298,"integrity":"sha512-u3Vp/nq93N1DuPs7ecO4SRRX/keMzX7dW/w7aTP4YiF7gW9w2QSf1B3a6xjkLZ+RETq7Ahl0d6NCynnsMcyaVg==","signatures":[{"sig":"MEYCIQCaT0hrc57HfADFBHgP0pC4E7HSL2TwMBkkwEdTwPGe2QIhAO7+LGR0woHA1JgD0azKWIWSc0E3lO7O58uXlYk8pDAT","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.23.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":3074821},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"dbb66a5ba14f2ba109cf0a627b269b08c29cb2f8","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/aahp-dashboard.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.19.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1","@babel/parser":"^7.29.7","@elvatis_com/aahp":"3.9.0","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.23.1_1785383545016_0.891847476351866","host":"s3://npm-registry-packages-npm-production"}},"5.23.2":{"name":"supply-chain-guard","version":"5.23.2","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.23.2","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"11312349fa60ff7110ea73a04f24482222530e50","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.23.2.tgz","fileCount":298,"integrity":"sha512-6VpKNoMpCfDk92D8i1VEBiCO0Eyn7RWsSGf+kcJHx7tIYQ3h1Lq1Nodd52Qy3h/iOeCan7cS0m+R+KKuKn3E2w==","signatures":[{"sig":"MEUCIQCFGuZ1d96AdIaa8po/1QLBqwIjaJ8Q7F0W/BjFb9blBwIgVimdE0d2x9lus7PTlRzqzaO0Q9D/uOVGXC6oGPZUGjM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.23.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":3198103},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"644c1e25b77c3593d09f5c838318db0e6e0d931a","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/aahp-dashboard.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.19.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1","@babel/parser":"^7.29.7","@elvatis_com/aahp":"3.9.0","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.23.2_1785390409236_0.37089642707475123","host":"s3://npm-registry-packages-npm-production"}},"5.23.3":{"name":"supply-chain-guard","version":"5.23.3","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.23.3","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"572205aec6bbad3fa8bec7ab5d1508204d3011d7","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.23.3.tgz","fileCount":298,"integrity":"sha512-YdYC5YI2hpy493VgLjRNdiNWTZ7JlmPddwwO6G9C6vrV5xRuAiTJLaKwVRpm0IgVflrxq9Sk3+G5TQKIRmq7ag==","signatures":[{"sig":"MEUCIQC6Lgcrocnmdes1vXAxTGyUFhc9jY3fuvLOHIHL654yoQIgZdGx2HfAypN+71ESDGSHfM1diW93A6nMds7zDma37ec=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.23.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":3525561},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"8227add9b89e1826c3fadd6d2f308e6ac06dd4f6","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/aahp-dashboard.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.19.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1","@babel/parser":"^7.29.7","@elvatis_com/aahp":"3.9.0","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.23.3_1785451073643_0.3382443651753091","host":"s3://npm-registry-packages-npm-production"}},"5.23.4":{"name":"supply-chain-guard","version":"5.23.4","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.23.4","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"1e09d51ed843dabafdd8ff90ca2f0b8171a173bb","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.23.4.tgz","fileCount":298,"integrity":"sha512-x6earlJZ+0nBNfJqRPq/BOL6bZwKQZ7s79Ov62yll1XyglvIwS7gG238MR25ujYaIVsNLt57tPMdt1cDZBBdFw==","signatures":[{"sig":"MEQCIAp6A65UEhxxpZZRM2aSndONs1HU3/zg35vkwt5Wi9ymAiBEB34Wz+6bXwGNrPoiWiDeIASblNeXnw+/fdR+3N17XA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.23.4","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":3616836},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"2154b3c5df9be7abcedafa02bc1c9844d326edca","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/aahp-dashboard.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.19.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1","@babel/parser":"^7.29.7","@elvatis_com/aahp":"3.9.0","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.23.4_1785488181721_0.7591869333175452","host":"s3://npm-registry-packages-npm-production"}},"5.23.5":{"name":"supply-chain-guard","version":"5.23.5","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.23.5","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"5e012df1b079ed70b703ce223264f8ce7e450d45","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.23.5.tgz","fileCount":298,"integrity":"sha512-3OniwKTJUI/f8fDNpuExEF2OyeE6ZcMU+C3ujPKPV6EeimBlfOSIazr3oniffThyfcq4OoBVwsFT22I88p421A==","signatures":[{"sig":"MEYCIQDEtaYny62mw0dGdqvY9yXNxgzdx1pTrIcH7zuw3E14WgIhAP/YFpvZ7isYRm12vV9gE8VGm0TCVKzBkxW2WBU5dl2b","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.23.5","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":3708728},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"e25837d342575c3e5e762eea1bb2523ccc736aef","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/aahp-dashboard.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.19.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1","@babel/parser":"^7.29.7","@elvatis_com/aahp":"3.9.0","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.23.5_1785571287077_0.8350928859928894","host":"s3://npm-registry-packages-npm-production"}},"5.24.0":{"name":"supply-chain-guard","version":"5.24.0","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.24.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"2ab834ae62790a2765a59b691e50a6d07eb03aa9","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.24.0.tgz","fileCount":298,"integrity":"sha512-wQ/dcLqj0Y971U5pXJrdJw8qmoow2b+pTGZ+LTaIkLFLUh6VgBmDWuFKCOo0wVk29yV7o+3OWlVGdxPVOUCYLg==","signatures":[{"sig":"MEUCIHsm8SlCAFz6PpaL3tQ4hh17goHLF6k7q5AU+8m36U+XAiEAoet/DK3KJa/gLBTYCscpaH+41DEjeEcBIc1M2F9504E=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.24.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":4875460},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"cc017bf7b353492c474bd51f63974ce40549af9e","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/aahp-dashboard.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.19.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1","@babel/parser":"^7.29.7","@elvatis_com/aahp":"3.9.0","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.24.0_1785655342861_0.85284740529567","host":"s3://npm-registry-packages-npm-production"}},"5.25.0":{"name":"supply-chain-guard","version":"5.25.0","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.25.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"07337b81b207cf2f9905bd2bb3efd8bef5e1795d","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.25.0.tgz","fileCount":298,"integrity":"sha512-bIU47uB4sXOKZMOqrJE4zWv0g3vcMwyOtv0bG3hDYZwZIOexcVpww9Khx0LeA2R7zcuZrrdI3MK6UtN4IIIv8g==","signatures":[{"sig":"MEQCICLFHbGYwXBQrGokVosti28k0lAvUlvGfiURf7Ui/pODAiBvMBOl6AyUSs+pHqpERfAHdZ60x6yVCwgDGLtU0jNAOg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.25.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":4917313},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"5b0df10eea04a55af6052fbd93c79e01e290c22d","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/aahp-dashboard.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.19.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1","@babel/parser":"^7.29.7","@elvatis_com/aahp":"3.9.0","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.25.0_1785746297171_0.4760495755809213","host":"s3://npm-registry-packages-npm-production"}},"5.25.1":{"name":"supply-chain-guard","version":"5.25.1","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.25.1","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"eb3908337da23997d394a50d4c0369338a065279","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.25.1.tgz","fileCount":298,"integrity":"sha512-inayy1eAHc7nrGA3dUxLgSofQiHoh7VwELymNwzdsv0m2jSSYZkVW3YjoZP4WNFbBtVb2ou03yPhFH8Qm00Dog==","signatures":[{"sig":"MEYCIQCY9hfxdLYgJM22etrJ1iDwzu5d2Nn6LH0PsCwozkZh3QIhALF5kGK3DlW2xqWlKqku2qldaA85Ijpn3fTZ7wYAY+Tb","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.25.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":4927695},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"28bbd9f5d31fdf2d0e18a30bde35c6710ce23b4b","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/aahp-dashboard.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.19.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.2","@babel/parser":"^7.29.7","@elvatis_com/aahp":"3.9.0","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.25.1_1785822360617_0.9102241341273776","host":"s3://npm-registry-packages-npm-production"}},"5.25.2":{"name":"supply-chain-guard","version":"5.25.2","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.25.2","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"4ab86f450c265deb197ded4f35eff7aece61ac09","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.25.2.tgz","fileCount":302,"integrity":"sha512-wkwG5HpLLNGhfSTWVxgUri4Myryf89+ohOT++sI+99OHJNZ2O6avBmQLB9wC2TKmkAiJw9mAwUwE2d5AeHj8YA==","signatures":[{"sig":"MEYCIQCU/+e+LjTT/PBKGX9S09iIy8bwloM65V8Qm0BlZ3dhXQIhAKJWRPhoqd2YfkIMa4ObtGpmadV4C29EjwulrqVq3vdb","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.25.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":4978718},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"0e68fef8a5b3cd272caf719bd0e7c7183d6ea79f","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/aahp-dashboard.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.2","@babel/parser":"^7.29.7","@elvatis_com/aahp":"3.9.1","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.25.2_1785834910231_0.7891504190602554","host":"s3://npm-registry-packages-npm-production"}},"5.25.3":{"name":"supply-chain-guard","version":"5.25.3","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.25.3","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"24a91c6753f17d5c60cc06bcdd20878a459fffc8","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.25.3.tgz","fileCount":302,"integrity":"sha512-70BybB0OiJ8UE6+sabXpt7aYXuM1p9u58KX4kv7/5+Ye8j4j0cQQB1957H2ZpD47lkPdeAXQiQjrF1Tbfc8jBA==","signatures":[{"sig":"MEYCIQDXi+abDuzJZbnm2+6+BF7KMcELB64F/qwPKFOaAA6epAIhAOGgHinWcL+jzv+XFRfDzqQivJe/lLTvI1mZJcNLC3eI","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.25.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":4978806},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"56137d4c4279239c42d10347c694f5fa1b7ceb54","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/aahp-dashboard.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.2","@babel/parser":"^7.29.7","@elvatis_com/aahp":"3.9.1","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.25.3_1785837074559_0.2667863190032187","host":"s3://npm-registry-packages-npm-production"}},"5.25.4":{"name":"supply-chain-guard","version":"5.25.4","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.25.4","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"80cc14a14571ae5d810c3ddee1ff01e2a3af56df","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.25.4.tgz","fileCount":302,"integrity":"sha512-u5bSli/fEs1Gmc/Qxef+SRpOzWokDC61+lXPCbd5IJSe+ki+1wu2/LbK/UgNLFUM6Tprf2KViI3dAPD9XM9TiQ==","signatures":[{"sig":"MEUCIFiOBJBA+TC1ES50FwE6XURWdEeeo5hJpaI8VS0jxPHjAiEAv2Th5No4ZbCYikRab++h2FUVb4u3tlAbuD+ljThZcrE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.25.4","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":5075166},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"e7effc4985c7828d76d1da4839e6c1ee875915d9","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/aahp-dashboard.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/aahp-dashboard.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.2","@babel/parser":"^7.29.7","@elvatis_com/aahp":"3.9.1","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.25.4_1785919050729_0.07363527433118033","host":"s3://npm-registry-packages-npm-production"}},"5.25.5":{"name":"supply-chain-guard","version":"5.25.5","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.25.5","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"8945eb87a8447f7b2a559fbe102bd6b1f84969b0","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.25.5.tgz","fileCount":302,"integrity":"sha512-FYbga6b2ehtGcpxyJYtAcjZVHU3yOmnsri2eq55fzPx5l5320BGE+3tpAGj/Ux/i+hSV7pcKnZwACTH2KWcAyg==","signatures":[{"sig":"MEYCIQCuMTWjWEpjkBUgNqvwy1GdC+HBhMim+U/MCtW2LNxtpQIhAPSro0xJbLFCh0j0uLkhtAsuT/PyHeFZlbKKye1PRKhk","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.25.5","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":5075614},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"8871f507671ebd1e068abbe6ce11e0ca07faa4bb","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/scg-handoff-docs.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.2","@babel/parser":"^7.29.7","@elvatis_com/aahp":"3.9.2","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.25.5_1785937242153_0.3603249685926604","host":"s3://npm-registry-packages-npm-production"}},"5.25.6":{"name":"supply-chain-guard","version":"5.25.6","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.25.6","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"8e3c363060c4c934d2496d30cf620aa117e8ca74","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.25.6.tgz","fileCount":302,"integrity":"sha512-i98kg/YAoc7FBpbxpzDMbX9mjKODlcODVpHYcOQvAW15t9hj5ZDVlOfKPGbq+lO8kyd32e2yWZiKKoVcH8LOOQ==","signatures":[{"sig":"MEUCIGQ1JPYQE4DrCHBY869MXBDlVudcMOIJGgi2AIlcK2I+AiEAoL8rJoLIhN+7zpYOJB9xL7aUjRQ4NlLpiIAndAihlt8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.25.6","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":6035149},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"c40d603d428cc8cc3819fa79ae844e37da1894b4","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/scg-handoff-docs.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.2","@babel/parser":"^7.29.7","@elvatis_com/aahp":"3.9.2","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.25.6_1786006367385_0.09678659686957336","host":"s3://npm-registry-packages-npm-production"}},"5.25.7":{"name":"supply-chain-guard","version":"5.25.7","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.25.7","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"6a7e8cea56e57009de1546b0d4311c21d356e92a","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.25.7.tgz","fileCount":302,"integrity":"sha512-nCdcw0g0Egth3WD98jDoB7eR4IloU4TaSpu0T1mUyla0Yvg0q6N9pN4/RaOHOkikRanh/luTLh3Yk7N8ttRl4A==","signatures":[{"sig":"MEYCIQCtVE1lKwaKRMvlGuMb4qlg/JwIo3Chx4viLFeLO2xUmQIhAO981l9C7mBQ7LwXB3wLRkAYgqy/RHzwsRloPSWx0fLx","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.25.7","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":6286942},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"5f37e55aaadb9a4a7e118c1a2259eb190387f3a1","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/scg-handoff-docs.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.2","@babel/parser":"^7.29.7","@elvatis_com/aahp":"3.9.2","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.25.7_1786085545689_0.5307932857816946","host":"s3://npm-registry-packages-npm-production"}},"5.25.8":{"name":"supply-chain-guard","version":"5.25.8","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.25.8","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"0a81a8f1f383e9583889a97d468ffe2bb2b0d594","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.25.8.tgz","fileCount":302,"integrity":"sha512-OWyQta5gBj9oc2qfy5yGX41Po/EkL31maNg1p9J/gnhkLEfMyNTZdO1f5g49pPftoBGXyBqpjSsVFSUEiFh0TQ==","signatures":[{"sig":"MEQCIAPFj83ZUPCooB7uImtRN5A1Op+XauodMIjadmoH/MJlAiAp5inu7ZB3fV+O4aDxBfmnqrBvaVaJCdiGt273ahejMg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.25.8","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":6375250},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"7afaedcdb4967b1a6c856b52888ead3f7dc907eb","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/scg-handoff-docs.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.2","@babel/parser":"^7.29.7","@elvatis_com/aahp":"3.9.2","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.25.8_1786181525553_0.7313675097836041","host":"s3://npm-registry-packages-npm-production"}},"5.25.9":{"name":"supply-chain-guard","version":"5.25.9","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.25.9","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"b042fcb6a2a8104b4b2bab45bcf35c5143f99fdb","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.25.9.tgz","fileCount":302,"integrity":"sha512-uNZbT8kUE5sJgf+3qe4FeyZxKSKknQ2w3Z1/fDWXytbfbx0Ck+Sazyqs/x9/AtsyD5kC7l/uRTLy6piRXlCKCg==","signatures":[{"sig":"MEYCIQDB7GkF//VtSIM2VzIoN0B0UVh7W8aS7SGHch61z2Ou+gIhAJJ4UYoKNj4/Udxhb0q/uZCjyQ1WNnUN/YikSpsSp6Yd","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.25.9","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":6410113},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"186ff846239a4de51411c172bceddcf630a1ce83","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/scg-handoff-docs.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.2","@babel/parser":"^7.29.7","@elvatis_com/aahp":"3.9.2","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.25.9_1786268282237_0.4371797856363815","host":"s3://npm-registry-packages-npm-production"}},"5.25.10":{"name":"supply-chain-guard","version":"5.25.10","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.25.10","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"cc87bbf6eec8105c90dc927ef87306ae524aab0b","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.25.10.tgz","fileCount":302,"integrity":"sha512-GtuBKmE4M9RoJJKNO0XEM1NVDXd0jvXjvlJS3RNZv/Rq1DorMgiRvHc7Csbgx0Tca+GIYsFdEhBq0aWe9w6NKw==","signatures":[{"sig":"MEQCIF21Icsj4+vRIlrtVWiTpwLfIoiZp+c9wMLal0zAXG0eAiAVoffCKxq5gVZNl2EU8VWQKhmqfkzGQU87w0x4kJB+iQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.25.10","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":6490325},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"00c9fcf6713a333da13a0557c53dc7b6e59aa5eb","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/scg-handoff-docs.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.2","@babel/parser":"^7.29.7","@elvatis_com/aahp":"3.9.2","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.25.10_1786346418887_0.4992595863639242","host":"s3://npm-registry-packages-npm-production"}},"5.25.11":{"name":"supply-chain-guard","version":"5.25.11","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.25.11","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"0d1918198b48ae5af80b15a3e51a2c240f84a8bd","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.25.11.tgz","fileCount":302,"integrity":"sha512-N/HrDSK1KzFHSZdiZhWucTDEMRXZTX9x1D7SAnXF95YWXB/MnTJ0A9Qtv5cGMVV/c/45nFgSOFCIODSgxauMDg==","signatures":[{"sig":"MEUCIG5kTKQihWEkEwhUPYHaWVxYECRSRiBcYoHpxYZvymnAAiEA5RIaTABbrkNF0PEkmOppTYsUN+77LyFr67OevtKHZYo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.25.11","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":6543250},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"e64f72aced3b46507919f647fe9a7b9010363777","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/scg-handoff-docs.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.2","@babel/parser":"^7.29.7","@elvatis_com/aahp":"3.9.2","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.25.11_1786442505711_0.0984310176057086","host":"s3://npm-registry-packages-npm-production"}},"5.25.12":{"name":"supply-chain-guard","version":"5.25.12","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.25.12","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"e8fd5ff8b1dfa458c0f8d3bbca19597096cdf3d0","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.25.12.tgz","fileCount":302,"integrity":"sha512-ZoRi5WXpQTj9EB5je60t/PvCFLjtUM1gnEcIM8fXWtsi+JGYubMwhiLULS3auE4XQ3Gb8fLawNZNtIVUBHoROw==","signatures":[{"sig":"MEUCIGHuj2hztYBy5AbVxtq3XRJkndno6+JIu+1Uhq2HNWonAiEA0t3j/Qam3JHEGezavmODnc+a59DvesVCzWK/DuN8wqw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.25.12","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":6571352},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"35ec4c7c29357bc6ad9e5fde24e889c58694cb0e","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/scg-handoff-docs.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.2","@babel/parser":"^7.29.7","@elvatis_com/aahp":"3.9.2","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.25.12_1786522602339_0.8766485794926928","host":"s3://npm-registry-packages-npm-production"}},"5.26.0":{"name":"supply-chain-guard","version":"5.26.0","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.26.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"d94b5b94742f38318575f5c618a3cde7bcb5d9d2","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.26.0.tgz","fileCount":302,"integrity":"sha512-kFpyIbONggK4q2PFowkMJhCJrgf5dt7Us9Dz5B/UduLwwKLE1XcuYU+15xxujcUuwOVnrwIm55NOX5j6H9QITg==","signatures":[{"sig":"MEUCIHhRMX8wN7AtZEnIWZQ0d+hYafndlFrUPF+sPV0sNqMvAiEAunEnVRPqUoyrFkC2kngmTgacwUiywH/YQmLHprNZqM0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.26.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":6599528},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"7ec1e6fdf14cd49771d418e29287e8afd4a7668a","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/scg-handoff-docs.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.2","@babel/parser":"^7.29.7","@elvatis_com/aahp":"3.9.2","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.26.0_1786527525222_0.6251520133351762","host":"s3://npm-registry-packages-npm-production"}},"5.26.1":{"name":"supply-chain-guard","version":"5.26.1","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.26.1","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"5813dba4628651dfdb0e4bddfb4d2cf3cf61d6a2","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.26.1.tgz","fileCount":302,"integrity":"sha512-S0Y8LxjZTIm+9AAXeZeV/4hTV9nerzn5Bv/IZdNzXgRo5lGxZYOMzrBsUgoyiRpfSkS21CWPWGMNGwtG0SoceQ==","signatures":[{"sig":"MEQCIBfPsckxp8k8t1Q8j8B6nWEWLoiSSLTPQnTjt6SSlh0KAiA7toVu7SVHzsT3TxaYZv/65Yh7FrTGUlE/znhFtnI76Q==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.26.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":6683516},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"8b642a8d56553714878509165bd180da0ca9d719","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/scg-handoff-docs.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.2","@babel/parser":"^7.29.7","@elvatis_com/aahp":"3.9.2","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.26.1_1786604880855_0.76642543701794","host":"s3://npm-registry-packages-npm-production"}},"5.26.2":{"name":"supply-chain-guard","version":"5.26.2","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.26.2","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"8713b55a5b45741f339e4c13751c69f770424bde","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.26.2.tgz","fileCount":302,"integrity":"sha512-vow3y3bHsMicnBmj5nbEufLzIH4XcbCfIsH0/8UuMJS2tBiclx+7Th+AsjItUgFc3wkcWNw8UkgtPla9wiudeQ==","signatures":[{"sig":"MEUCIA4vKng+8pLpvAOXfg6S+Dz4n6UxsQnH9+QjXUV28vcJAiEA5gzKg+LSUBIHtD0X1Ui3e6BSpORgLaTn3FsjpHZbKBI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.26.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":6734858},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"a323b941abdb358bbc9151f62a715a28978ba18d","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/scg-handoff-docs.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.2","@babel/parser":"^7.29.7","@elvatis_com/aahp":"3.9.2","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.26.2_1786703176565_0.23628030153063628","host":"s3://npm-registry-packages-npm-production"}},"5.26.3":{"name":"supply-chain-guard","version":"5.26.3","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.26.3","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"3692ba6e351cc8688821e81c23167cb91856e0d3","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.26.3.tgz","fileCount":302,"integrity":"sha512-sVobiMLsFoyRQCuY63mGZFKuaUkZOwxI1IM/63j9g1phnxYsnDmbvhAg+k9qiQggpQlQKlTKetotkef0b6rK5Q==","signatures":[{"sig":"MEUCIQCOzoEHkvi+zd8JHHp0KXcrtXYsMENsu3FHB2ou4SXc7QIgLlx1vlLxEMaMVpaEgzV3z9VB/vn+v10J4TdZoPQHP5s=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.26.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":6815754},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"88a7056079762c83fb2a0b39a790ce8c399b2635","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/scg-handoff-docs.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.2","@babel/parser":"^7.29.7","@elvatis_com/aahp":"3.9.2","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.26.3_1786786874638_0.2479001056714636","host":"s3://npm-registry-packages-npm-production"}},"5.26.4":{"name":"supply-chain-guard","version":"5.26.4","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.26.4","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"da32e2923b556d52c913fc3d89aa50fe2d90524f","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.26.4.tgz","fileCount":302,"integrity":"sha512-gp5j3I0tPIGVYbssyZgSotgjJ8D0sEkuWiaeEMG+LwacZ+ImsMNJ8JC3w5MF8iJLzRt0G3NNytZGSdszV8jUbg==","signatures":[{"sig":"MEUCIQDr0OVtNYOOAOkpOrzSqy2R51s6rAMfQC2t/q5ugkAbOwIgJkVOmkuDIJrdQv0VIDndAMtQpQrGLHRvJUfdKC3gCO0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.26.4","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":6892342},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"c2054ab1d5040a5a9f4e340f553f8d327a06c7d1","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/scg-handoff-docs.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.2","@babel/parser":"^7.29.7","@elvatis_com/aahp":"3.9.2","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.26.4_1786876636230_0.9535695192132252","host":"s3://npm-registry-packages-npm-production"}},"5.26.5":{"name":"supply-chain-guard","version":"5.26.5","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.26.5","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"946d6fc398d2e31504987b4037ec74481a828b5e","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.26.5.tgz","fileCount":302,"integrity":"sha512-hwx/r+LD4rlv7bfJ1SI3cQlR6fUCpSMl5OhUqvcLDBcHmo/02DlMvX0ASpQhGE+JqZa1KYhNBheBZMLHnkOB6g==","signatures":[{"sig":"MEQCIGwiNo8rp3J9c1szoiQ6YhZmfJBt/HgKvOs4e23YhHqeAiBsFIfcnmlC9lpIyirLXMotD3o+H2TSPiCTQ5skAdDH3Q==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.26.5","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":6978401},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"090ef0724f353e4df9ce3dd622778c2be8d0fbb8","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/scg-handoff-docs.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.2","@babel/parser":"^7.29.7","@elvatis_com/aahp":"3.9.2","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.26.5_1786949211834_0.9090796229890057","host":"s3://npm-registry-packages-npm-production"}},"5.26.6":{"name":"supply-chain-guard","version":"5.26.6","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.26.6","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"4dc9ea0850a48203fd7ff2ff1d07d7210809def7","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.26.6.tgz","fileCount":302,"integrity":"sha512-rIJ/wxavHWagv4xLF33GZNO9kN/rQD8NSKz0JpFHopSw9k8dVSavw+GW3tg0jAprbyGREJ4+5ZmBBBElmDTGsw==","signatures":[{"sig":"MEUCIQDazoUnUGSXUF2cZFTSIu9TwJUg2AwggOld2HZSp2KWpgIgK3RDvmUlMsQf5vmw+Vn6WbC3/vjanvnRjCGRB5t0drQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.26.6","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":7056120},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"c5be80d82df25c7cbf02e3fe56dc169ccc3649e2","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/scg-handoff-docs.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.2.0","@babel/parser":"^7.29.7","@elvatis_com/aahp":"3.9.2","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.26.6_1787039677101_0.6286171413484638","host":"s3://npm-registry-packages-npm-production"}},"5.26.7":{"name":"supply-chain-guard","version":"5.26.7","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.26.7","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"163c7d14a44f3a6bcdb7d7242ff94ba21a65e41c","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.26.7.tgz","fileCount":302,"integrity":"sha512-SUuV/N6fvRTb3wmAC8xKZNg5AmI8Ac1kVGRhrgf/Lt2V7Xm3aEPHcYfqMYJ7sJ6Nnz/xwsUNu+hdUoSorKw3Mg==","signatures":[{"sig":"MEYCIQChebAMHWPvPgaa9Qq6C3jkz0r1itjcin9mvdCAUJTzMQIhAKkLS/AO0pc8tVlmbvscYCSf+oI9P9GVfoz+M/xYeGnr","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.26.7","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":7119745},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"010eb779ded592942584fcf356b79ed61b0e5d73","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/scg-handoff-docs.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.2.0","@babel/parser":"^7.29.7","@elvatis_com/aahp":"3.9.2","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.26.7_1787123974574_0.45174905102552","host":"s3://npm-registry-packages-npm-production"}},"5.27.0":{"name":"supply-chain-guard","version":"5.27.0","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.27.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"ba34f73eeecf5f7b105714081461cfff07a41da3","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.27.0.tgz","fileCount":302,"integrity":"sha512-Kb0FRmsto2kbXD0sJ3qpbej3rqbdD+O00vqnColQSqxDHLY+A8fVZSsSYrOcxfyQNb3SWwZXbTqxMFq/cUaGtA==","signatures":[{"sig":"MEUCIGnlikJ7EJFz/NQqstu4vhlnKYxIVi7w6d0ek8NSF9qJAiEA0tjIFAVBRRqiXlSmzJBviQS7PjcSmfkU+f7gx3pBt6w=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.27.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":7170042},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"7fc7de8a227981ca8e202001e0fcdb29f20d97a1","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/scg-handoff-docs.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"20.20.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.2.0","@babel/parser":"^7.29.7","@elvatis_com/aahp":"3.9.2","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.27.0_1787212562160_0.36439207494837134","host":"s3://npm-registry-packages-npm-production"}},"5.28.0":{"name":"supply-chain-guard","version":"5.28.0","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.28.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"441bf8cdea20e5a9d90ae8d7ffafac71f4b51f9b","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.28.0.tgz","fileCount":302,"integrity":"sha512-Phh6V/A6tFLhRRJP05EtcfrEJ54WVMgF4L7yVkRK9r/bzmdY7pnVw7iJk2TR+vkvj9HKtQU4yF7cDbSfNnM9JA==","signatures":[{"sig":"MEYCIQChHD5B0wWw5qgePPHICLkvqiizeS2vDEyj58KCMFClhQIhAN4l7NEwBXHnpctMOAUWFALslAJGv/TYtHpZcKnH/X/4","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.28.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":7183052},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"bc2f5556edac118c7f53432e03ca7fd8e3d61ce4","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"node scripts/check-aahp-pin.mjs && npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/scg-handoff-docs.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"22.23.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.2.0","@babel/parser":"^7.29.7","@elvatis_com/aahp":"3.9.2","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.28.0_1787230359110_0.576568783968805","host":"s3://npm-registry-packages-npm-production"}},"5.28.1":{"name":"supply-chain-guard","version":"5.28.1","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@5.28.1","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"77a0256083f1321c3db5abb316dcbec766969a00","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-5.28.1.tgz","fileCount":302,"integrity":"sha512-4Qgj9z4kcr1uMxpFhsNG6lkAmsQkzeJI+jLjYbl2DjepN+k26nSt3N6uzJQieiWsu1kBldQfoAK6WuYmg7OpJA==","signatures":[{"sig":"MEUCIBqhw4ivjJIVh6ikxJWraA57aZD4Ws5P5LXNdYVLeFHNAiEAt40l1Q+RTJHBFjwgkdqMOCn2x0MDdX8etcbwS1J+2HE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@5.28.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":7213754},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"fc8fb8f4989cd1960f48833fbaa1f726df897bbc","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"node scripts/check-aahp-pin.mjs && npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/scg-handoff-docs.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"22.23.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.2.0","@babel/parser":"^7.29.7","@elvatis_com/aahp":"3.9.2","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_5.28.1_1787301181145_0.36232933437679127","host":"s3://npm-registry-packages-npm-production"}},"6.0.0":{"name":"supply-chain-guard","version":"6.0.0","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@6.0.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"87b9124e22534fea1b0197185ef0f4ccf65bf4b2","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-6.0.0.tgz","fileCount":306,"integrity":"sha512-zBncKNHKh1U52OQ2WjooFy1frrdBwc1vM6dE9DDps6NlGbJvJ6JTO9gXw5Jt2jsxqEIJMOI80Ztg5vUvyeE+dg==","signatures":[{"sig":"MEYCIQD3tPNzux6/o8MiJiHocMtCREVzLmiWfhbRZSCjoq8pYAIhAO/Ib4UXA/5n2F1g4Jqb7W4/aP+/vaGG2j54ifrgEKPy","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@6.0.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":7621390},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"d4639fcd012c9babb762d342852d4930c3b9cdc8","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"node scripts/check-aahp-pin.mjs && node scripts/check-em-dash-scope.mjs && npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/scg-handoff-docs.mjs","check:release-ancestry":"node scripts/check-release-ancestry.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"22.23.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.2.0","ajv-formats":"^3.0.1","@babel/parser":"^7.29.7","packageurl-js":"^2.0.1","@elvatis_com/aahp":"3.10.0","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_6.0.0_1787485793999_0.9306002481497129","host":"s3://npm-registry-packages-npm-production"}},"6.0.1":{"name":"supply-chain-guard","version":"6.0.1","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@6.0.1","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"773b22971868dad1e46bfb5b85b97936345c11f0","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-6.0.1.tgz","fileCount":306,"integrity":"sha512-6sTKvX6cMEkuS1J8KZ+6R1vxH1/5DA4rm+aceS9BZVId7NyjIcNlKvgtk/eZUS2eSlIjVv14EVeJk4035P9jOQ==","signatures":[{"sig":"MEYCIQCfZziGg83mGtzpnAoNvfIYqLY5taY7B1fja9/DKXaWcAIhAN1fW7+5P5V4QbiTau5wfgu6XbxBFT6r7o5QQJJDP5ag","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@6.0.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":7633564},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"22f11bb11b646ff29426a0c53e724618e41f9452","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"node scripts/check-aahp-pin.mjs && node scripts/check-em-dash-scope.mjs && npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/scg-handoff-docs.mjs","check:release-ancestry":"node scripts/check-release-ancestry.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"22.23.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.2.0","ajv-formats":"^3.0.1","@babel/parser":"^7.29.7","packageurl-js":"^2.0.1","@elvatis_com/aahp":"3.10.0","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_6.0.1_1787560261426_0.22120000243871352","host":"s3://npm-registry-packages-npm-production"}},"6.0.2":{"name":"supply-chain-guard","version":"6.0.2","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@6.0.2","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"ea6e9482438ea308f8c45dc7e8ea9da233347e25","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-6.0.2.tgz","fileCount":306,"integrity":"sha512-iSmQ/4izLeQu+cxgkffKyklDzTgrjCvYMmNDen3AvslNFBiPKjR5CD6JVHhpBJTf41vSErM/c8nLCetbd45yPQ==","signatures":[{"sig":"MEQCIHgCsMsrbOtZLnNjbGaoJSq9ru4fj3AAFDINZFNSMkwPAiAmm6kHK0sF7lomCi4jq/+2ENmYn3f8/E/ruHdoS4Mu7A==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@6.0.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":7670971},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"d993d34a822e2761bf8334380a9b1b040ba247da","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"node scripts/check-aahp-pin.mjs && node scripts/check-em-dash-scope.mjs && npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/scg-handoff-docs.mjs","check:release-ancestry":"node scripts/check-release-ancestry.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"22.23.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","vitest":"^4.1.11","typescript":"^7.0.2","@types/node":"^26.2.0","ajv-formats":"^3.0.1","@babel/parser":"^7.29.7","packageurl-js":"^2.0.1","@elvatis_com/aahp":"3.10.0","@vitest/coverage-v8":"^4.1.11"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_6.0.2_1787645205829_0.3388533397363154","host":"s3://npm-registry-packages-npm-production"}},"6.0.3":{"name":"supply-chain-guard","version":"6.0.3","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@6.0.3","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"f423b70291711dc6c26d8cbb725320a97e6cad37","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-6.0.3.tgz","fileCount":306,"integrity":"sha512-1WVpA185sr/kNC9ZGjv31zA7qRqjhMhuNnsbO9rD0oOcL+4Q/bE+f318cdpBlKs4BU8HIvL6ffid0p+WxyeKlg==","signatures":[{"sig":"MEQCIDh+WltEZm9GeG33GGfM0Vb4auxwCHhk8SSjLO6PLltQAiBGr84sKoh/WpwPlTkQiWz6sK0fW1qLIAjqAJ2AtEKPow==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@6.0.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":7722186},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"45b9a60690af11ab8b1c4200ae31d7b293a732ea","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"node scripts/check-aahp-pin.mjs && node scripts/check-em-dash-scope.mjs && npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/scg-handoff-docs.mjs","check:release-ancestry":"node scripts/check-release-ancestry.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"22.23.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","vitest":"^4.1.11","typescript":"^7.0.2","@types/node":"^26.2.0","ajv-formats":"^3.0.1","@babel/parser":"^7.29.7","packageurl-js":"^2.0.1","@elvatis_com/aahp":"3.10.0","@vitest/coverage-v8":"^4.1.11"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_6.0.3_1787734748763_0.8906837078492678","host":"s3://npm-registry-packages-npm-production"}},"6.0.4":{"name":"supply-chain-guard","version":"6.0.4","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@6.0.4","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"5f3142da441a901e9575be7eaa2bf3ef1324cce3","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-6.0.4.tgz","fileCount":306,"integrity":"sha512-uUO7+3QTXa2HzPHTH4fDvc8Nkccw9aC711jsG8Fk0gvTYwQdsOW3+87W3npxPs4FrCszqQWVq1JgNvETPR/HAA==","signatures":[{"sig":"MEUCIQCuKYbW3dgLC7ESgflVyiCn0IL6umGaAWzD54Ogz0zfsQIgfd761Q8lWv869iuFPfeIXGVa/nTPukMoWWeviUuXZl0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@6.0.4","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":7733558},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"43a4ce588d3d92dc1ccf1e2f2fe04e8ac6b208c7","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"node scripts/check-aahp-pin.mjs && node scripts/check-em-dash-scope.mjs && npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/scg-handoff-docs.mjs","check:release-ancestry":"node scripts/check-release-ancestry.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"22.23.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","vitest":"^4.1.11","typescript":"^7.0.2","@types/node":"^26.2.0","ajv-formats":"^3.0.1","@babel/parser":"^7.29.7","packageurl-js":"^2.0.1","@elvatis_com/aahp":"3.10.0","@vitest/coverage-v8":"^4.1.11"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_6.0.4_1787813833676_0.12068385363467504","host":"s3://npm-registry-packages-npm-production"}},"6.0.5":{"name":"supply-chain-guard","version":"6.0.5","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@6.0.5","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"164c3abaa6f05f67ff0839f62dec7bec46922a2c","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-6.0.5.tgz","fileCount":306,"integrity":"sha512-V3K2BKWrkv7anrjwPzqpvAO6OyDe6xz7mo69InEugdfrQWCslf6iXE01prK0h+BwfNXLQpBjZS/il61No/1eXA==","signatures":[{"sig":"MEUCIDoTJi54//GYhJHvKC41SQUMZCmsM9+pnZ/5mulyrn1CAiEA1zPsS2IYqxHgEzNPJiBrPIJlaxrUyw/cqpkx+7C6byo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@6.0.5","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":7812129},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"aad997c7e5359495b155477709886e627f7feb05","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"node scripts/check-aahp-pin.mjs && node scripts/check-em-dash-scope.mjs && npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","handoff:refresh":"node scripts/scg-handoff-docs.mjs","check:release-ancestry":"node scripts/check-release-ancestry.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"22.23.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","vitest":"^4.1.11","typescript":"^7.0.2","@types/node":"^26.2.0","ajv-formats":"^3.0.1","@babel/parser":"^7.29.7","packageurl-js":"^2.0.1","@elvatis_com/aahp":"3.10.0","@vitest/coverage-v8":"^4.1.11"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_6.0.5_1787922866604_0.6923023959617942","host":"s3://npm-registry-packages-npm-production"}},"6.0.6":{"name":"supply-chain-guard","version":"6.0.6","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@6.0.6","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"9ae53ac8d1d222f8a11d0bcaeee837ff5503adfe","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-6.0.6.tgz","fileCount":310,"integrity":"sha512-DKa/FRDbFKMmBlV4gYBuw4h0y91iVZmZYgBUo1aUGy66Jvth5Nx4C6rVh25mRE884nZ12yh1cQogO7GZQnxNlw==","signatures":[{"sig":"MEUCIQD8C9ybYugFNPAf0cWt3neBdhQF8oc60DXIdZhGV+zjbAIgWtwIJYXov9sVLbXS2ZxkTV7sgFNzGMQIZWLh+d6AfEg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@6.0.6","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":7915070},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"37ffcbdf2284c39c48ce825fafd01770ee4bb027","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"node scripts/check-aahp-pin.mjs && node scripts/check-em-dash-scope.mjs && npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","audit:blocklist":"node scripts/audit-blocklist.mjs","handoff:refresh":"node scripts/scg-handoff-docs.mjs","check:release-ancestry":"node scripts/check-release-ancestry.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"22.23.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","vitest":"^4.1.11","typescript":"^7.0.2","@types/node":"^26.2.0","ajv-formats":"^3.0.1","@babel/parser":"^7.29.7","packageurl-js":"^2.0.1","@elvatis_com/aahp":"3.10.0","@vitest/coverage-v8":"^4.1.11"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_6.0.6_1788006500084_0.17456893031269405","host":"s3://npm-registry-packages-npm-production"}},"6.0.7":{"name":"supply-chain-guard","version":"6.0.7","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@6.0.7","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"8a561805337414f06d162c447c634fc52e4ebc69","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-6.0.7.tgz","fileCount":310,"integrity":"sha512-6raacrn/xTuBdwT1iWyL0vPaUbLohIVOXa38XHCSLpYc87EhHHQiq2PoRGrPfnRKMGPzQzmmrNA9yM7pgVcrug==","signatures":[{"sig":"MEQCIDiYOxaj7muMJn4WxIXWP5GiXbDrTAYaBmwopzqjYEdHAiBPPYx/U+HzJ4JHAIcjhtV3e5sZI+pMGsN14nsqTw36KA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@6.0.7","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":8006939},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"37b26d23cb63402826703f8bef24676902068d56","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff","check:aahp":"node scripts/check-aahp-pin.mjs && node scripts/check-em-dash-scope.mjs && npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build","audit:blocklist":"node scripts/audit-blocklist.mjs","handoff:refresh":"node scripts/scg-handoff-docs.mjs","check:release-ancestry":"node scripts/check-release-ancestry.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"22.23.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","vitest":"^4.1.11","typescript":"^7.0.2","@types/node":"^26.2.0","ajv-formats":"^3.0.1","@babel/parser":"^7.29.7","packageurl-js":"^2.0.1","@elvatis_com/aahp":"3.10.0","@vitest/coverage-v8":"^4.1.11"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_6.0.7_1788087064248_0.4271614089459961","host":"s3://npm-registry-packages-npm-production"}},"6.0.8":{"name":"supply-chain-guard","version":"6.0.8","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@6.0.8","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"fe2079e3761247a24c3b9496fa3c6ef8a2412425","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-6.0.8.tgz","fileCount":316,"integrity":"sha512-gQXk8V7HQM5njRl44siplZdmNnCL6GUTvOfGKC5yecdLlfx1ETDH34ZtlBRvr1zkSXqJWMSHEHaEuW6iiNdU7Q==","signatures":[{"sig":"MEQCIExwsjgUo2B0QtAXvuXfTgrkfHMwXFgctsXtq7AqYeukAiBCmFbM7ZoSlWVA8wKyzJ+0xuq7HCGxmBOCLqFUOiubAQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@6.0.8","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":8356946},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"2ba749d08e19b4d5c75c71467233987748f8e8c7","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"node scripts/run-vitest-clean.mjs","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff && npm run check:self-scan","check:aahp":"node scripts/check-aahp-pin.mjs && node scripts/check-em-dash-scope.mjs && npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"node scripts/run-vitest-clean.mjs --coverage","prepublishOnly":"npm run build","audit:blocklist":"node scripts/audit-blocklist.mjs","check:self-scan":"node scripts/generate-self-scan-manifest.mjs --check","handoff:refresh":"node scripts/scg-handoff-docs.mjs","self-scan:generate":"node scripts/generate-self-scan-manifest.mjs","check:release-ancestry":"node scripts/check-release-ancestry.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"22.23.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","vitest":"^4.1.11","typescript":"^7.0.2","@types/node":"^26.2.0","ajv-formats":"^3.0.1","@babel/parser":"^7.29.7","packageurl-js":"^2.0.1","@elvatis_com/aahp":"3.10.0","@vitest/coverage-v8":"^4.1.11"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_6.0.8_1788173400580_0.25935122668275223","host":"s3://npm-registry-packages-npm-production"}},"6.0.9":{"name":"supply-chain-guard","version":"6.0.9","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@6.0.9","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"5e038f67bb6846187781a10dbceac731af902b90","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-6.0.9.tgz","fileCount":316,"integrity":"sha512-+65Nj+8zmPIuGC7ZMGCIfjg1SHp+ELriuKfzzwOafLrRMvK2ScwmVeELA4GD0XzWvq7aUe0Vk40VJOOV/xcNNg==","signatures":[{"sig":"MEUCIEKBovPubS5ebhXe4TNzMzRNc3mi8tJQSsRl2ugB6xf1AiEA7Z1M3AOQzv5zNV5hWhvmDgwkFLgllsukJ8duwLM5d40=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@6.0.9","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":9713865},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"e8a3e27e1039f32df64d62c5a626710d07c3a963","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"node scripts/run-vitest-clean.mjs","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff && npm run check:self-scan","check:aahp":"node scripts/check-aahp-pin.mjs && node scripts/check-em-dash-scope.mjs && npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"node scripts/run-vitest-clean.mjs --coverage","prepublishOnly":"npm run build","audit:blocklist":"node scripts/audit-blocklist.mjs","check:self-scan":"node scripts/generate-self-scan-manifest.mjs --check","handoff:refresh":"node scripts/scg-handoff-docs.mjs","self-scan:generate":"node scripts/generate-self-scan-manifest.mjs","check:release-ancestry":"node scripts/check-release-ancestry.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"22.23.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","vitest":"^4.1.11","typescript":"^7.0.2","@types/node":"^26.4.0","ajv-formats":"^3.0.1","@babel/parser":"^7.29.7","packageurl-js":"^2.0.1","@elvatis_com/aahp":"3.12.0","@vitest/coverage-v8":"^4.1.11"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_6.0.9_1788251912636_0.18101655259095262","host":"s3://npm-registry-packages-npm-production"}},"6.0.10":{"name":"supply-chain-guard","version":"6.0.10","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@6.0.10","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"cd5a23b8d98129ea9c977607da89c2d6bcf9b8d9","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-6.0.10.tgz","fileCount":316,"integrity":"sha512-t4eJACzV9SKUArRNVBrmx/faYpvJ5keXjlZENlBm2sYmb4ppRD8XW0V/1RgXbYfLIw07Cw2pFm9MIWq+KSnZaQ==","signatures":[{"sig":"MEQCIDMxWUEFE3aUrW1y4mrMaSS9GiS9aDc7uQg1bQDvUUfIAiAmXVJOtlzbhNiuQLXmVpUUe1OJzwQWes2yEv6Lqsh9Qw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@6.0.10","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":9863902},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"a1cb3464689c2bdfb46fca45e3ceffa496a747ba","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"node scripts/run-vitest-clean.mjs","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff && npm run check:self-scan","check:aahp":"node scripts/check-aahp-pin.mjs && node scripts/check-em-dash-scope.mjs && npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"node scripts/run-vitest-clean.mjs --coverage","prepublishOnly":"npm run build","audit:blocklist":"node scripts/audit-blocklist.mjs","check:self-scan":"node scripts/generate-self-scan-manifest.mjs --check","handoff:refresh":"node scripts/scg-handoff-docs.mjs","self-scan:generate":"node scripts/generate-self-scan-manifest.mjs","check:release-ancestry":"node scripts/check-release-ancestry.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"22.23.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","vitest":"^4.1.11","typescript":"^7.0.2","@types/node":"^26.4.0","ajv-formats":"^3.0.1","@babel/parser":"^7.29.7","packageurl-js":"^2.0.1","@elvatis_com/aahp":"3.12.0","@vitest/coverage-v8":"^4.1.11"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_6.0.10_1788337095593_0.30513332208051547","host":"s3://npm-registry-packages-npm-production"}},"6.0.11":{"name":"supply-chain-guard","version":"6.0.11","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@6.0.11","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"9fd724e338bc582ca471f9448e5dc40a49ba8c1f","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-6.0.11.tgz","fileCount":316,"integrity":"sha512-4L168yUQqZt5rhmx1k+BGeg8Jsvy4hpeo5EYaoBe4RtgeZqdNOx6m2nI6AFXKIMSLiy/ZGO/vA6yz+dtoEIT4Q==","signatures":[{"sig":"MEYCIQCfK4q7LxIf1dQJ5osKJaUPU2GbUserpStfOO5Z60qVOgIhAIv/GPlaczLDtRVO1sBLEI6eze9uynTh7S3szEwQRdOe","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@6.0.11","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":9877546},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"bebc58156621bb1cca365b35c7fa79bf8ef8a869","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"node scripts/run-vitest-clean.mjs","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff && npm run check:self-scan","check:aahp":"node scripts/check-aahp-pin.mjs && node scripts/check-em-dash-scope.mjs && npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"node scripts/run-vitest-clean.mjs --coverage","prepublishOnly":"npm run build","audit:blocklist":"node scripts/audit-blocklist.mjs","check:self-scan":"node scripts/generate-self-scan-manifest.mjs --check","handoff:refresh":"node scripts/scg-handoff-docs.mjs","self-scan:generate":"node scripts/generate-self-scan-manifest.mjs","check:release-ancestry":"node scripts/check-release-ancestry.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"22.23.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","vitest":"^4.1.11","typescript":"^7.0.2","@types/node":"^26.4.0","ajv-formats":"^3.0.1","@babel/parser":"^7.29.7","packageurl-js":"^2.0.1","@elvatis_com/aahp":"3.12.0","@vitest/coverage-v8":"^4.1.11"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_6.0.11_1788420106568_0.8127875631857375","host":"s3://npm-registry-packages-npm-production"}},"6.0.12":{"name":"supply-chain-guard","version":"6.0.12","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@6.0.12","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"a8f1031b33342077a1195915773fc3f1d9c5f40e","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-6.0.12.tgz","fileCount":316,"integrity":"sha512-hF0YspTnO/Br4Cs1aG8asqLBfLrVGWVYoGLbQurLgfBQG1rt/kv7CdOSuARiLJrtlm7a8Smg6BwWeg1gkd8KKA==","signatures":[{"sig":"MEQCIHCaF1s0exMrT09nFSwVVGjk29DazdypQ0bwLiFMTzQAAiB6DcvwP5W825c/Y5WuBAkf31oC8I8MG6sOCeyZJGe3jw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@6.0.12","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":9918337},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"5a6ae75d0ef609963409e7b47bfdd373492aef61","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"node scripts/run-vitest-clean.mjs","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff && npm run check:self-scan","check:aahp":"node scripts/check-aahp-pin.mjs && node scripts/check-em-dash-scope.mjs && npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"node scripts/run-vitest-clean.mjs --coverage","prepublishOnly":"npm run build","audit:blocklist":"node scripts/audit-blocklist.mjs","check:self-scan":"node scripts/generate-self-scan-manifest.mjs --check","handoff:refresh":"node scripts/scg-handoff-docs.mjs","self-scan:generate":"node scripts/generate-self-scan-manifest.mjs","check:release-ancestry":"node scripts/check-release-ancestry.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"22.23.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","vitest":"^4.1.11","typescript":"^7.0.2","@types/node":"^26.4.0","ajv-formats":"^3.0.1","@babel/parser":"^7.29.7","packageurl-js":"^2.0.1","@elvatis_com/aahp":"3.12.0","@vitest/coverage-v8":"^4.1.11"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_6.0.12_1788513062479_0.187520457260844","host":"s3://npm-registry-packages-npm-production"}},"6.0.13":{"name":"supply-chain-guard","version":"6.0.13","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@6.0.13","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"4dbb587102d199ab27aa128f3204957ee09af63a","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-6.0.13.tgz","fileCount":316,"integrity":"sha512-N2lgSAPl1X+UvtDyZZlYyLEMeDnDttJn9PLI1htU4F4sc0WPqANSRSpvvMugrt/4eAzKafUeMoW9GJKkIDVb1w==","signatures":[{"sig":"MEYCIQDecoc5LqC/nLbB2tMq8D7C1v5AODvgPaofC+0kMy+t/QIhAKFb37GydlQTaIJZ0418ATevA4aFkeKEzdM1bpoDF0+H","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@6.0.13","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":9927069},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"e84a0643df90c8e3c5035b0c8141348d7625445c","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"node scripts/run-vitest-clean.mjs","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff && npm run check:self-scan","check:aahp":"node scripts/check-aahp-pin.mjs && node scripts/check-em-dash-scope.mjs && npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"node scripts/run-vitest-clean.mjs --coverage","prepublishOnly":"npm run build","audit:blocklist":"node scripts/audit-blocklist.mjs","check:self-scan":"node scripts/generate-self-scan-manifest.mjs --check","handoff:refresh":"node scripts/scg-handoff-docs.mjs","self-scan:generate":"node scripts/generate-self-scan-manifest.mjs","check:release-ancestry":"node scripts/check-release-ancestry.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"22.23.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","vitest":"^4.1.11","typescript":"^7.0.2","@types/node":"^26.4.0","ajv-formats":"^3.0.1","@babel/parser":"^7.29.7","packageurl-js":"^2.0.1","@elvatis_com/aahp":"3.12.0","@vitest/coverage-v8":"^4.1.11"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_6.0.13_1788587627477_0.6829084618207069","host":"s3://npm-registry-packages-npm-production"}},"6.0.14":{"name":"supply-chain-guard","version":"6.0.14","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@6.0.14","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"b47b8075a61095a9f3bda923dba8a4a6c2a4cab7","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-6.0.14.tgz","fileCount":316,"integrity":"sha512-N8S2GE51isGjXXcineFaZ3GD6n9RqU4zqW4dMB9974FPezoXBGmpezj2pMZrp0AB5G8mdowF5neFF4YU0TR5tQ==","signatures":[{"sig":"MEUCICekbdUbCBvu2V0NJzn6uAElcbvaIDvBAa1gPuodmubJAiEA4ip3iJgv6TNiTaFXNOxqKRg5Fj/0fqhE6cnePmWihyA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@6.0.14","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":9944642},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"201d5de0facce24c2c2e7fd18cb12ec8ab0400a2","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"node scripts/run-vitest-clean.mjs","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff && npm run check:self-scan","check:aahp":"node scripts/check-aahp-pin.mjs && node scripts/check-em-dash-scope.mjs && npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"node scripts/run-vitest-clean.mjs --coverage","prepublishOnly":"npm run build","audit:blocklist":"node scripts/audit-blocklist.mjs","check:self-scan":"node scripts/generate-self-scan-manifest.mjs --check","handoff:refresh":"node scripts/scg-handoff-docs.mjs","self-scan:generate":"node scripts/generate-self-scan-manifest.mjs","check:release-ancestry":"node scripts/check-release-ancestry.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"22.23.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","vitest":"^4.1.11","typescript":"^7.0.2","@types/node":"^26.4.0","ajv-formats":"^3.0.1","@babel/parser":"^7.29.7","packageurl-js":"^2.0.1","@elvatis_com/aahp":"3.12.0","@vitest/coverage-v8":"^4.1.11"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_6.0.14_1788691729759_0.7588674596543923","host":"s3://npm-registry-packages-npm-production"}},"6.0.15":{"name":"supply-chain-guard","version":"6.0.15","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@6.0.15","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"7d8bb8febbc3890efcd241054e3ab998b0202e1d","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-6.0.15.tgz","fileCount":316,"integrity":"sha512-rM9MJ4XjVEWR4Z+sx3aV4UbEB/75byWdWqLyHjS74M1mJf0G83SoSJp40tBRGkDGmFj9ZAkhPM0121Ayr/Miow==","signatures":[{"sig":"MEQCIDIQniujIwXZSZDrrXEkqlmXpcBCS6dmdXi+5sNAeJagAiAOtnlMaPQ19BQiBCUHhIc54WEiyhCOB/3pjv7MZgXCCQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@6.0.15","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":9951848},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"0dedc46c8f1e2828918823a813bf91d7909d6943","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"node scripts/run-vitest-clean.mjs","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff && npm run check:self-scan","check:aahp":"node scripts/check-aahp-pin.mjs && node scripts/check-em-dash-scope.mjs && npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"node scripts/run-vitest-clean.mjs --coverage","prepublishOnly":"npm run build","audit:blocklist":"node scripts/audit-blocklist.mjs","check:self-scan":"node scripts/generate-self-scan-manifest.mjs --check","handoff:refresh":"node scripts/scg-handoff-docs.mjs","self-scan:generate":"node scripts/generate-self-scan-manifest.mjs","check:release-ancestry":"node scripts/check-release-ancestry.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"22.23.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","vitest":"^4.1.11","typescript":"^7.0.2","@types/node":"^26.4.0","ajv-formats":"^3.0.1","@babel/parser":"^7.29.7","packageurl-js":"^2.0.1","@elvatis_com/aahp":"3.12.0","@vitest/coverage-v8":"^4.1.11"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_6.0.15_1788760397604_0.23293090883407386","host":"s3://npm-registry-packages-npm-production"}},"6.0.16":{"name":"supply-chain-guard","version":"6.0.16","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@6.0.16","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"a55835ee641ca47050cd8b22076bf13b24918c14","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-6.0.16.tgz","fileCount":316,"integrity":"sha512-2lsgzawlsyJsDwv/W6j6OGDSYigKGf49Mf2IIdEu1KOXQkusOH4W7sMzuy9JQIb/c6tt9/RD2B0hBCGSMDCHcg==","signatures":[{"sig":"MEUCIQDeiNZLLJy/7Iw1iVcXcAIv/mbC1h3y3qh37BExFHhQ+AIgT9f233cwNBGVXuUPYe/i4KOduSKAa1EA2S8gNesfKZI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@6.0.16","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":9995234},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"0f8b9a44c09b9adea3014e51283145e5f3e7139c","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"node scripts/run-vitest-clean.mjs","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff && npm run check:self-scan","check:aahp":"node scripts/check-aahp-pin.mjs && node scripts/check-em-dash-scope.mjs && npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"node scripts/run-vitest-clean.mjs --coverage","prepublishOnly":"npm run build","audit:blocklist":"node scripts/audit-blocklist.mjs","check:self-scan":"node scripts/generate-self-scan-manifest.mjs --check","handoff:refresh":"node scripts/scg-handoff-docs.mjs","self-scan:generate":"node scripts/generate-self-scan-manifest.mjs","check:release-ancestry":"node scripts/check-release-ancestry.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"22.23.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","vitest":"^4.1.11","typescript":"^7.0.2","@types/node":"^26.4.0","ajv-formats":"^3.0.1","@babel/parser":"^7.29.7","packageurl-js":"^2.0.1","@elvatis_com/aahp":"3.12.0","@vitest/coverage-v8":"^4.1.11"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_6.0.16_1788852721635_0.013305786920859708","host":"s3://npm-registry-packages-npm-production"}},"6.0.17":{"name":"supply-chain-guard","version":"6.0.17","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@6.0.17","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"039bea7114fb146d6c5e305ceeec8d70baca35e2","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-6.0.17.tgz","fileCount":316,"integrity":"sha512-Gyi5Bxxnm3UdUw1t6ENqpDytoQXcXRhwL6ptdFTMXAiFHMStMeGgNS/z+fAsmvH7JhP8hbaZHiltVEstnd+igw==","signatures":[{"sig":"MEQCIBMrei3m5dENZCL6VQIC+LousuxpLtEg8GPlt9X29j5EAiBmdt1za9eOZtHSyZ979MgeOYkWRItC2l6a2+n2LgX51A==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@6.0.17","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":10020920},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"225f9ee1f4d5036530941c18446454855235a440","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"node scripts/run-vitest-clean.mjs","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff && npm run check:self-scan","check:aahp":"node scripts/check-aahp-pin.mjs && node scripts/check-em-dash-scope.mjs && npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"node scripts/run-vitest-clean.mjs --coverage","prepublishOnly":"npm run build","audit:blocklist":"node scripts/audit-blocklist.mjs","check:self-scan":"node scripts/generate-self-scan-manifest.mjs --check","handoff:refresh":"node scripts/scg-handoff-docs.mjs","self-scan:generate":"node scripts/generate-self-scan-manifest.mjs","check:release-ancestry":"node scripts/check-release-ancestry.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"22.23.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","ajv-formats":"^3.0.1","@babel/parser":"^7.29.7","packageurl-js":"^2.0.1","@elvatis_com/aahp":"3.12.0","@vitest/coverage-v8":"^5.0.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_6.0.17_1788947348988_0.3805591721689361","host":"s3://npm-registry-packages-npm-production"}},"6.0.18":{"name":"supply-chain-guard","version":"6.0.18","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@6.0.18","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"87e8204e8ca7582ae90bf7e33d3cd630b0d0f7af","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-6.0.18.tgz","fileCount":316,"integrity":"sha512-wmvMQgjm+HPFj7mUMggvKqRlmBbjYZd3Kb5mqz+yUny5xi8hqNcNqEn1PYp/jCitbUur2NFx9KDZH645nWJ1HQ==","signatures":[{"sig":"MEYCIQD1ZU4otyGt0RcKzj7c6RhY0oRsVC9OkU2znzGUjiKSkgIhAMBeaJ8n0rNk4VUl1pL3BPaasAvT1xdKh6L3euT1BCyn","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@6.0.18","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":10038175},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"cb33e1db56eba00a9d1169716e12b4c8c6d9bf65","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"node scripts/run-vitest-clean.mjs","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff && npm run check:self-scan","check:aahp":"node scripts/check-aahp-pin.mjs && node scripts/check-em-dash-scope.mjs && npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"node scripts/run-vitest-clean.mjs --coverage","prepublishOnly":"npm run build","audit:blocklist":"node scripts/audit-blocklist.mjs","check:self-scan":"node scripts/generate-self-scan-manifest.mjs --check","handoff:refresh":"node scripts/scg-handoff-docs.mjs","self-scan:generate":"node scripts/generate-self-scan-manifest.mjs","check:release-ancestry":"node scripts/check-release-ancestry.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"22.23.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","ajv-formats":"^3.0.1","@babel/parser":"^7.29.7","packageurl-js":"^2.0.1","@elvatis_com/aahp":"3.12.0","@vitest/coverage-v8":"^5.0.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_6.0.18_1789021714772_0.21236131613163645","host":"s3://npm-registry-packages-npm-production"}},"6.0.19":{"name":"supply-chain-guard","version":"6.0.19","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@6.0.19","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"1ad4f996e43f0c217c3f6f0f94708f54bdade7ff","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-6.0.19.tgz","fileCount":316,"integrity":"sha512-Mdq+WCyyMl+gAGj/wwMKNDANOeYBHR0oxFAfJ/6bfOW9Qj5WRqfUh9FUm5oSjZ+/sjDFNuObdxKgJG2YQShiCw==","signatures":[{"sig":"MEUCIGJxnNCLkzYo7NLzpqYzScPr1sm8ut1RXwmXBJYy8AWuAiEA6hJdtpZoH7cFv/L2yAvNy3UQ+qak9tEw6ZMPM1UFD54=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@6.0.19","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":10065140},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"f57bb231c44b4f7b88842817391ab279a755799a","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"node scripts/run-vitest-clean.mjs","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff && npm run check:self-scan","check:aahp":"node scripts/check-aahp-pin.mjs && node scripts/check-em-dash-scope.mjs && npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"node scripts/run-vitest-clean.mjs --coverage","prepublishOnly":"npm run build","audit:blocklist":"node scripts/audit-blocklist.mjs","check:self-scan":"node scripts/generate-self-scan-manifest.mjs --check","handoff:refresh":"node scripts/scg-handoff-docs.mjs","self-scan:generate":"node scripts/generate-self-scan-manifest.mjs","check:release-ancestry":"node scripts/check-release-ancestry.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"22.23.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","ajv-formats":"^3.0.1","@babel/parser":"^7.29.7","packageurl-js":"^2.0.1","@elvatis_com/aahp":"3.12.0","@vitest/coverage-v8":"^5.0.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_6.0.19_1789115040341_0.7569315957181566","host":"s3://npm-registry-packages-npm-production"}},"6.0.20":{"name":"supply-chain-guard","version":"6.0.20","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@6.0.20","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"7cc315968c8780a867a03ee0ca52688a743e869c","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-6.0.20.tgz","fileCount":316,"integrity":"sha512-5JjfunNQGzaVPblq5zgHsfTWed8mZ7Z19XdXj5wIsFz6Gg42tRyvhBUSRwWOGwPGNx9of15t06Dy2vnfXLLc5g==","signatures":[{"sig":"MEUCIBkOQnoUb7qiuvTefGw3GeRgon27G0swK8pYeX6LMywHAiEAnBTrKsZlrqCDo509DSqoUN7xahQbYHUpDyqTn+Zg/6Y=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@6.0.20","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":10090840},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"2f29bee997a051010517702b6ccbecc46260187a","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"node scripts/run-vitest-clean.mjs","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff && npm run check:self-scan","check:aahp":"node scripts/check-aahp-pin.mjs && node scripts/check-em-dash-scope.mjs && npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"node scripts/run-vitest-clean.mjs --coverage","prepublishOnly":"npm run build","audit:blocklist":"node scripts/audit-blocklist.mjs","check:self-scan":"node scripts/generate-self-scan-manifest.mjs --check","handoff:refresh":"node scripts/scg-handoff-docs.mjs","self-scan:generate":"node scripts/generate-self-scan-manifest.mjs","check:release-ancestry":"node scripts/check-release-ancestry.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"22.23.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","ajv-formats":"^3.0.1","@babel/parser":"^7.29.7","packageurl-js":"^2.0.1","@elvatis_com/aahp":"3.12.0","@vitest/coverage-v8":"^5.0.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_6.0.20_1789200044961_0.4754963959158329","host":"s3://npm-registry-packages-npm-production"}},"6.1.0":{"name":"supply-chain-guard","version":"6.1.0","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@6.1.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"093881b9e5ad198e734d9c132dcb411626cc328e","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-6.1.0.tgz","fileCount":324,"integrity":"sha512-Xoim9bW8aVEdTDFLcrlt8l5AUMzVPmTdxwTrVDhZf2gLpeVVAuCoC8CENDTgyTQh7nUva6gx8GCQ/iuDQKjeBw==","signatures":[{"sig":"MEUCIQCk0cDPgDFil9rH1hAcm9gvbRKV3euT+0bUP1t2JebbOQIgWTWsqQEc6GxTsg2Yz7S6B/1VsEfp5RnunkWcNa1Rc6g=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@6.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":10306206},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"985478b908eedc646d58173df05ef5b4613b7127","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"node scripts/run-vitest-clean.mjs","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff && npm run check:self-scan","check:aahp":"node scripts/check-aahp-pin.mjs && node scripts/check-em-dash-scope.mjs && npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"node scripts/run-vitest-clean.mjs --coverage","prepublishOnly":"npm run build","audit:blocklist":"node scripts/audit-blocklist.mjs","check:self-scan":"node scripts/generate-self-scan-manifest.mjs --check","handoff:refresh":"node scripts/scg-handoff-docs.mjs","self-scan:generate":"node scripts/generate-self-scan-manifest.mjs","check:release-ancestry":"node scripts/check-release-ancestry.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"22.23.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","ajv-formats":"^3.0.1","@babel/parser":"^7.29.7","packageurl-js":"^2.0.1","@elvatis_com/aahp":"3.12.0","@vitest/coverage-v8":"^5.0.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_6.1.0_1789309513241_0.827010852073288","host":"s3://npm-registry-packages-npm-production"}},"6.1.1":{"name":"supply-chain-guard","version":"6.1.1","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@6.1.1","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"36ec71e0a9de70c2d6efd9e234334cbfe99ef5c4","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-6.1.1.tgz","fileCount":324,"integrity":"sha512-wmHt67BxY9Wc+aaXNJD0l3+A1/FGGAksXsBCn9KCy0hhgUA56tql3FPnECdIa4sWEgb7MhcDgMwPJK1wknc9xQ==","signatures":[{"sig":"MEUCIAniCQ1vQ5dkg8jkJLwh5fk3H1BPnaKuZrgnHSGOaq4XAiEAi019dA5uhFI/wNS3MdFDlH96AF5c/JxI89y5WTrFYAQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@6.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":10309334},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"2a0ca143e82dbf4ea4215295d988f44ec0cc35ef","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"node scripts/run-vitest-clean.mjs","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff && npm run check:self-scan","check:aahp":"node scripts/check-aahp-pin.mjs && node scripts/check-em-dash-scope.mjs && npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"node scripts/run-vitest-clean.mjs --coverage","prepublishOnly":"npm run build","audit:blocklist":"node scripts/audit-blocklist.mjs","check:self-scan":"node scripts/generate-self-scan-manifest.mjs --check","handoff:refresh":"node scripts/scg-handoff-docs.mjs","self-scan:generate":"node scripts/generate-self-scan-manifest.mjs","check:release-ancestry":"node scripts/check-release-ancestry.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"22.23.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.5.1","ajv-formats":"^3.0.1","@babel/parser":"^8.0.5","packageurl-js":"^2.0.1","@elvatis_com/aahp":"3.12.0","@vitest/coverage-v8":"^5.0.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_6.1.1_1789411793155_0.3061008894065267","host":"s3://npm-registry-packages-npm-production"}},"6.1.2":{"name":"supply-chain-guard","version":"6.1.2","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@6.1.2","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"7835f68d5b2cb92315ccd00588cf3c762dc72a2e","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-6.1.2.tgz","fileCount":324,"integrity":"sha512-fk67SckV5mdwoTr6sR153Z2rOjbaAf5oYLLDBiY2BAAIjQa8z/dYON4yEoSO23srx8mUyjXdHOZ9YkyzhUInkg==","signatures":[{"sig":"MEQCIGn6ue6jDn+sa9XnXRUrdm5UQqTJgMvFc3sk6ocpP6nQAiB4d12tH9ZpOWJCZOkXfzntXWhirs3CMVY28h1TZ/s1hA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@6.1.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":10339817},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"1b74f56be41045dba9f37925379f244a9304d0b6","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"node scripts/run-vitest-clean.mjs","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff && npm run check:self-scan","check:aahp":"node scripts/check-aahp-pin.mjs && node scripts/check-em-dash-scope.mjs && npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"node scripts/run-vitest-clean.mjs --coverage","prepublishOnly":"npm run build","audit:blocklist":"node scripts/audit-blocklist.mjs","check:self-scan":"node scripts/generate-self-scan-manifest.mjs --check","handoff:refresh":"node scripts/scg-handoff-docs.mjs","self-scan:generate":"node scripts/generate-self-scan-manifest.mjs","check:release-ancestry":"node scripts/check-release-ancestry.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"22.23.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.5.1","ajv-formats":"^3.0.1","@babel/parser":"^8.0.5","packageurl-js":"^2.0.1","@elvatis_com/aahp":"3.12.0","@vitest/coverage-v8":"^5.0.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_6.1.2_1789470953540_0.8032355929264672","host":"s3://npm-registry-packages-npm-production"}},"6.1.3":{"name":"supply-chain-guard","version":"6.1.3","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@6.1.3","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"4c913ef58e71cae28dad4377a96ac12a92093ecf","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-6.1.3.tgz","fileCount":324,"integrity":"sha512-L20b7ktuYjORfLQZA22uDAeC596Uxe9dSM5cw8rFrIryr2c+Qb56x1bwcrmGPqeTF/WzyFym3qftPbyayk/Mew==","signatures":[{"sig":"MEUCIQDs/TD4n/4ZUoFV9tPEPAK6GK2QPGy8G1KwB12dGWCZ0gIgEiJeenp3TuTWeSEDjPbtVZyMfcgAkDDTThPD8UO6QlE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@6.1.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":10388138},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"05c07297b22c6ec8c53cc34a9fda4f6bc3ccc9d9","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"node scripts/run-vitest-clean.mjs","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:handoff && npm run check:self-scan","check:aahp":"node scripts/check-aahp-pin.mjs && node scripts/check-em-dash-scope.mjs && npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"node scripts/run-vitest-clean.mjs --coverage","prepublishOnly":"npm run build","audit:blocklist":"node scripts/audit-blocklist.mjs","check:self-scan":"node scripts/generate-self-scan-manifest.mjs --check","handoff:refresh":"node scripts/scg-handoff-docs.mjs","self-scan:generate":"node scripts/generate-self-scan-manifest.mjs","check:release-ancestry":"node scripts/check-release-ancestry.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"22.23.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.5.1","ajv-formats":"^3.0.1","@babel/parser":"^8.0.5","packageurl-js":"^2.0.1","@elvatis_com/aahp":"3.12.0","@vitest/coverage-v8":"^5.0.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_6.1.3_1789562973711_0.9747934202572757","host":"s3://npm-registry-packages-npm-production"}},"6.2.0":{"name":"supply-chain-guard","version":"6.2.0","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@6.2.0","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"f8ea72b6393871e08a4c653f3b14d803503c662f","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-6.2.0.tgz","fileCount":328,"integrity":"sha512-bbSHWasXxuIAIKQ3Xl2HwA0jN0q/eMP/W5DGLM8LBSSoSLf+fsm4VjnNjwIwtBf9euK58vh9sw++qmN7pT3g/Q==","signatures":[{"sig":"MEQCIBVS80R0m3NdduSGsC6E+eFDF5NAj0CQLccWyHnE/PdEAiBT0AOzY1Z0x6n5N0KxtiiSAZ0w7kz4zIkrBJ1p1nrfTQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@6.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":6717572},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"3c2628c59763caa4e4be23634ba8582a5c68b98c","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"node scripts/run-vitest-clean.mjs","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:feed-partition && npm run check:feed-budget && npm run check:catalog && npm run check:handoff && npm run check:self-scan","check:aahp":"node scripts/check-aahp-pin.mjs && node scripts/check-em-dash-scope.mjs && npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","feed:migrate":"node scripts/feed-migrate.mjs","check:catalog":"node scripts/generate-catalog.mjs --check","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"node scripts/run-vitest-clean.mjs --coverage","prepublishOnly":"npm run build","audit:blocklist":"node scripts/audit-blocklist.mjs","check:self-scan":"node scripts/generate-self-scan-manifest.mjs --check","handoff:refresh":"node scripts/scg-handoff-docs.mjs","release:prepare":"node scripts/release-prepare.mjs","catalog:generate":"node scripts/generate-catalog.mjs","check:feed-budget":"node scripts/check-feed-budget.mjs","self-scan:generate":"node scripts/generate-self-scan-manifest.mjs","check:feed-partition":"node scripts/check-feed-partition.mjs","check:release-ancestry":"node scripts/check-release-ancestry.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"22.23.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.5.1","ajv-formats":"^3.0.1","@babel/parser":"^8.0.5","packageurl-js":"^2.0.1","@elvatis_com/aahp":"3.12.0","@vitest/coverage-v8":"^5.0.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_6.2.0_1789638184515_0.07018206704510188","host":"s3://npm-registry-packages-npm-production"}},"6.2.1":{"name":"supply-chain-guard","version":"6.2.1","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@6.2.1","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"ab2ee5f3795d1543fb2f0b6436723d5d4f9197e0","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-6.2.1.tgz","fileCount":328,"integrity":"sha512-rrJusqFwDinOZVk6mfk1Bfeitpa4UZ5nC4JOdjLq+blZAFCCZV1WBsdp2UwgSxh9AJkhG+f9P56l0dq6uDyazg==","signatures":[{"sig":"MEYCIQCxAzJbcfLVuti/2kfslys/dKz4RbIqyEhk2gci/kUdwgIhANAzoLRqf+cDzqPahtMh+LEnVMZm9OpTh5nh/ElkgSHQ","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@6.2.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":6649948},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"8cec5c31841cdb88a6be993d5029077fa5821eac","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"node scripts/run-vitest-clean.mjs","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:feed-partition && npm run check:feed-budget && npm run check:catalog && npm run check:handoff && npm run check:self-scan","check:aahp":"node scripts/check-aahp-pin.mjs && node scripts/check-em-dash-scope.mjs && npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","feed:migrate":"node scripts/feed-migrate.mjs","check:catalog":"node scripts/generate-catalog.mjs --check","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"node scripts/run-vitest-clean.mjs --coverage","prepublishOnly":"npm run build","audit:blocklist":"node scripts/audit-blocklist.mjs","check:self-scan":"node scripts/generate-self-scan-manifest.mjs --check","handoff:refresh":"node scripts/scg-handoff-docs.mjs","release:prepare":"node scripts/release-prepare.mjs","catalog:generate":"node scripts/generate-catalog.mjs","check:feed-budget":"node scripts/check-feed-budget.mjs","self-scan:generate":"node scripts/generate-self-scan-manifest.mjs","check:feed-partition":"node scripts/check-feed-partition.mjs","check:release-ancestry":"node scripts/check-release-ancestry.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"22.23.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.5.1","ajv-formats":"^3.0.1","@babel/parser":"^8.0.5","packageurl-js":"^2.0.1","@elvatis_com/aahp":"3.12.0","@vitest/coverage-v8":"^5.0.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_6.2.1_1789809389274_0.47148305888700515","host":"s3://npm-registry-packages-npm-production"}},"6.2.2":{"name":"supply-chain-guard","version":"6.2.2","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@6.2.2","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"79ef7b3bd116cf63e505cefa7c7adefe567cff0d","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-6.2.2.tgz","fileCount":328,"integrity":"sha512-m5ukjXjijByWpzQAUvY5b4sOJurEnWIKnQYvFmf/Op7sU6ndsIQhDHs3cgGNzOiNLGWN8tOxHROi7VtQiDG9pg==","signatures":[{"sig":"MEYCIQCRpXqTT/U2gb4AGEwgBjBqJEds7TQnr2mmFb/lcPtiHAIhAIjcqsbXRpp0sTqgxJ3L5QsiwOIhjf32ynXwLC7EjSpl","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@6.2.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":6629441},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"74eb299bd080e06845ff39c580e6b99a6697fe87","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"node scripts/run-vitest-clean.mjs","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:feed-partition && npm run check:feed-budget && npm run check:catalog && npm run check:handoff && npm run check:self-scan","check:aahp":"node scripts/check-aahp-pin.mjs && node scripts/check-em-dash-scope.mjs && npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","feed:migrate":"node scripts/feed-migrate.mjs","check:catalog":"node scripts/generate-catalog.mjs --check","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"node scripts/run-vitest-clean.mjs --coverage","prepublishOnly":"npm run build","audit:blocklist":"node scripts/audit-blocklist.mjs","check:self-scan":"node scripts/generate-self-scan-manifest.mjs --check","handoff:refresh":"node scripts/scg-handoff-docs.mjs","release:prepare":"node scripts/release-prepare.mjs","catalog:generate":"node scripts/generate-catalog.mjs","check:feed-budget":"node scripts/check-feed-budget.mjs","self-scan:generate":"node scripts/generate-self-scan-manifest.mjs","check:feed-partition":"node scripts/check-feed-partition.mjs","check:release-ancestry":"node scripts/check-release-ancestry.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"22.23.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.5.1","ajv-formats":"^3.0.1","@babel/parser":"^8.0.5","packageurl-js":"^2.0.1","@elvatis_com/aahp":"3.12.0","@vitest/coverage-v8":"^5.0.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_6.2.2_1789922407214_0.9483641943952283","host":"s3://npm-registry-packages-npm-production"}},"6.2.3":{"name":"supply-chain-guard","version":"6.2.3","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@6.2.3","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"f8c1db82178ecf07fee33bcb33965b0a107cbc40","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-6.2.3.tgz","fileCount":328,"integrity":"sha512-BhTU6X50imxt/ye6EOqeNScc7aWTj0BzJwjvJWNURA3xpugvpQVjuH8i8ctqqpiNhENQPaiUn67CGSu54IEEYg==","signatures":[{"sig":"MEUCIQCJ0tIbQGYbZT78LZjJOw+DlMjRx14k3RaIdGXwuVpj2AIgBOgpx4UU7dic4DghsqkGh+nf9dIKir5f7ePeStrPiRM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@6.2.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":6642693},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"642cfd6b6bde5f8100b5df3996d6632a156d84bd","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"node scripts/run-vitest-clean.mjs","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:feed-partition && npm run check:feed-budget && npm run check:catalog && npm run check:handoff && npm run check:self-scan","check:aahp":"node scripts/check-aahp-pin.mjs && node scripts/check-em-dash-scope.mjs && npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","feed:migrate":"node scripts/feed-migrate.mjs","check:catalog":"node scripts/generate-catalog.mjs --check","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"node scripts/run-vitest-clean.mjs --coverage","prepublishOnly":"npm run build","audit:blocklist":"node scripts/audit-blocklist.mjs","check:self-scan":"node scripts/generate-self-scan-manifest.mjs --check","handoff:refresh":"node scripts/scg-handoff-docs.mjs","release:prepare":"node scripts/release-prepare.mjs","catalog:generate":"node scripts/generate-catalog.mjs","check:feed-budget":"node scripts/check-feed-budget.mjs","self-scan:generate":"node scripts/generate-self-scan-manifest.mjs","check:feed-partition":"node scripts/check-feed-partition.mjs","check:release-ancestry":"node scripts/check-release-ancestry.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"22.23.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.5.1","ajv-formats":"^3.0.1","@babel/parser":"^8.0.5","packageurl-js":"^2.0.1","@elvatis_com/aahp":"3.12.0","@vitest/coverage-v8":"^5.0.0"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_6.2.3_1789972233241_0.8455420950802175","host":"s3://npm-registry-packages-npm-production"}},"6.2.4":{"name":"supply-chain-guard","version":"6.2.4","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@6.2.4","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"2c38214bcb94422daa029ecea03aa30c1aee214f","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-6.2.4.tgz","fileCount":328,"integrity":"sha512-I8ZUEcJPFsjlX54wfJOd8sRA20/ABslyBjMmDbGLh3cRFsYcc1W9XfVCnwxvIlKKP//n5o7140I3iJeDeonTRw==","signatures":[{"sig":"MEUCIQCwzwEo2wTNI8iZVRFmGh20+P7ueGHGBnZQvXQeY7h/5wIgT5YmTmcYI5G2aXvWoToCkkq9SK4OPKnU0ODm84MjDYg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@6.2.4","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":6666670},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"36dba1a9913c3641bc1e5b88a957f451e72210e9","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"node scripts/run-vitest-clean.mjs","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:feed-partition && npm run check:feed-budget && npm run check:catalog && npm run check:handoff && npm run check:self-scan","check:aahp":"node scripts/check-aahp-pin.mjs && node scripts/check-em-dash-scope.mjs && npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","feed:migrate":"node scripts/feed-migrate.mjs","check:catalog":"node scripts/generate-catalog.mjs --check","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"node scripts/run-vitest-clean.mjs --coverage","prepublishOnly":"npm run build","audit:blocklist":"node scripts/audit-blocklist.mjs","check:self-scan":"node scripts/generate-self-scan-manifest.mjs --check","handoff:refresh":"node scripts/scg-handoff-docs.mjs","release:prepare":"node scripts/release-prepare.mjs","catalog:generate":"node scripts/generate-catalog.mjs","check:feed-budget":"node scripts/check-feed-budget.mjs","self-scan:generate":"node scripts/generate-self-scan-manifest.mjs","check:feed-partition":"node scripts/check-feed-partition.mjs","check:release-ancestry":"node scripts/check-release-ancestry.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"22.23.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","vitest":"^5.0.1","typescript":"^7.0.2","@types/node":"^26.6.1","ajv-formats":"^3.0.1","@babel/parser":"^8.0.6","packageurl-js":"^2.0.1","@elvatis_com/aahp":"3.12.0","@vitest/coverage-v8":"^5.0.1"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_6.2.4_1790061529190_0.056993400314180986","host":"s3://npm-registry-packages-npm-production"}},"6.2.5":{"name":"supply-chain-guard","version":"6.2.5","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","_id":"supply-chain-guard@6.2.5","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"homepage":"https://github.com/homeofe/supply-chain-guard#readme","bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"bin":{"supply-chain-guard":"dist/cli.js"},"dist":{"shasum":"0ec69acee36be189b02a96df0b635e315515abc8","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-6.2.5.tgz","fileCount":328,"integrity":"sha512-2776ox+3brxxlhy6kUFvylYcUKUoIOSknaTCETB7ORw2VK/6cIiyi7jANkPvmfpXvjOleMhA1Su/T08w1Mgbzw==","signatures":[{"sig":"MEUCIQDJKy/qQqJIKY/aSIL4erSan9u/DuaAO+OUMjiyo1CINAIgJRkdiW06K/7F/Se8Wxxv2zqQlpQFRQSxAJ2vExsDJNk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@6.2.5","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":6698129},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"89e7260856d3979234525a47b9bc753aaa6f0ce5","mcpName":"io.github.homeofe/supply-chain-guard","scripts":{"lint":"tsc --noEmit","test":"node scripts/run-vitest-clean.mjs","build":"tsc","prepare":"tsc","prebuild":"npm run check:aahp && npm run check:feed && npm run check:feed-partition && npm run check:feed-budget && npm run check:catalog && npm run check:handoff && npm run check:self-scan","check:aahp":"node scripts/check-aahp-pin.mjs && node scripts/check-em-dash-scope.mjs && npx --no-install aahp check .","check:feed":"node scripts/generate-feed.mjs --check","test:watch":"vitest","feed:import":"node scripts/import-threat-feed.mjs","feed:migrate":"node scripts/feed-migrate.mjs","check:catalog":"node scripts/generate-catalog.mjs --check","check:handoff":"node scripts/scg-handoff-docs.mjs --check","feed:generate":"node scripts/generate-feed.mjs","test:coverage":"node scripts/run-vitest-clean.mjs --coverage","prepublishOnly":"npm run build","audit:blocklist":"node scripts/audit-blocklist.mjs","check:self-scan":"node scripts/generate-self-scan-manifest.mjs --check","handoff:refresh":"node scripts/scg-handoff-docs.mjs","release:prepare":"node scripts/release-prepare.mjs","catalog:generate":"node scripts/generate-catalog.mjs","check:feed-budget":"node scripts/check-feed-budget.mjs","self-scan:generate":"node scripts/generate-self-scan-manifest.mjs","check:feed-partition":"node scripts/check-feed-partition.mjs","check:release-ancestry":"node scripts/check-release-ancestry.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"repository":{"url":"git+https://github.com/homeofe/supply-chain-guard.git","type":"git"},"_npmVersion":"11.18.0","description":"Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros","directories":{},"_nodeVersion":"22.23.2","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.20.0","vitest":"^5.0.1","typescript":"^7.0.2","@types/node":"^26.6.1","ajv-formats":"^3.0.1","@babel/parser":"^8.0.6","packageurl-js":"^2.0.1","@elvatis_com/aahp":"3.12.0","@vitest/coverage-v8":"^5.0.1"},"_npmOperationalInternal":{"tmp":"tmp/supply-chain-guard_6.2.5_1790149206765_0.36456644808231387","host":"s3://npm-registry-packages-npm-production"}},"6.3.0":{"name":"supply-chain-guard","version":"6.3.0","mcpName":"io.github.homeofe/supply-chain-guard","description":"Open-source supply-chain security scanner, local and offline. Matches known-malicious packages, extensions, plugins, providers, container images and CI actions in 15 ecosystems, including transitive lockfile dependencies at any depth, and detects GlassWor","main":"dist/index.js","types":"dist/index.d.ts","bin":{"supply-chain-guard":"dist/cli.js"},"scripts":{"build":"tsc","test":"node scripts/run-vitest-clean.mjs","test:coverage":"node scripts/run-vitest-clean.mjs --coverage","test:watch":"vitest","lint":"tsc --noEmit","check:aahp":"node scripts/check-aahp-pin.mjs && node scripts/check-em-dash-scope.mjs && npx --no-install aahp check .","check:handoff":"node scripts/scg-handoff-docs.mjs --check","check:self-scan":"node scripts/generate-self-scan-manifest.mjs --check","self-scan:generate":"node scripts/generate-self-scan-manifest.mjs","check:release-ancestry":"node scripts/check-release-ancestry.mjs","handoff:refresh":"node scripts/scg-handoff-docs.mjs","feed:generate":"node scripts/generate-feed.mjs","audit:blocklist":"node scripts/audit-blocklist.mjs","feed:import":"node scripts/import-threat-feed.mjs","feed:migrate":"node scripts/feed-migrate.mjs","catalog:generate":"node scripts/generate-catalog.mjs","check:catalog":"node scripts/generate-catalog.mjs --check","release:prepare":"node scripts/release-prepare.mjs","check:feed":"node scripts/generate-feed.mjs --check","check:feed-partition":"node scripts/check-feed-partition.mjs","check:feed-budget":"node scripts/check-feed-budget.mjs","prebuild":"npm run check:aahp && npm run check:feed && npm run check:coverage && npm run check:feed-partition && npm run check:feed-budget && npm run check:catalog && npm run check:handoff && npm run check:log-archive && npm run check:self-scan","prepublishOnly":"npm run build","prepare":"tsc","coverage:generate":"node scripts/generate-coverage-table.mjs","check:coverage":"node scripts/generate-coverage-table.mjs --check","check:log-archive":"npx --no-install aahp archive . --verify"},"keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence","maven","gradle","nuget","rubygems","composer","vscode-extensions","browser-extensions","homebrew","helm","lockfile"],"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","repository":{"type":"git","url":"git+https://github.com/homeofe/supply-chain-guard.git"},"bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"homepage":"https://github.com/homeofe/supply-chain-guard#readme","engines":{"node":">=22.0.0"},"dependencies":{"commander":"^14.0.3"},"devDependencies":{"@babel/parser":"^8.0.6","@elvatis_com/aahp":"3.12.0","@types/node":"^26.6.2","@vitest/coverage-v8":"^5.0.1","ajv":"^8.20.0","ajv-formats":"^3.0.1","fast-check":"4.10.2","packageurl-js":"^2.0.1","typescript":"^7.0.2","vitest":"^5.0.1"},"gitHead":"772bbefa9d83c627a9e1d94ce0c2367e3706de50","_id":"supply-chain-guard@6.3.0","_nodeVersion":"24.21.0","_npmVersion":"11.19.1","dist":{"integrity":"sha512-hnV2JEkYtWDSxviD/lkxM0JcK3yURwH/js8aRGc/YqMTe+iBhbF630jdG1aq2sDFNQcmsDdxnzaiXYz5rdS74Q==","shasum":"a96b07f90737ae5d675eddf1045e872eb1eb6854","tarball":"https://registry.npmjs.org/supply-chain-guard/-/supply-chain-guard-6.3.0.tgz","fileCount":368,"unpackedSize":7351903,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/supply-chain-guard@6.3.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCypCKZWCfq7rqiR7W+Iv0+aXeHkYPF04b2OyZdQ79xxgIhAKykW+DYnWwA1N+JzaVZKmvFVg5jrKmJLK604C3ms/3+"}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9862f9bb-fae1-42bf-9533-f305a9f91deb"}},"directories":{},"maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/supply-chain-guard_6.3.0_1790380881098_0.41274027570651306"},"_hasShrinkwrap":false}},"time":{"created":"2026-03-19T03:49:01.670Z","modified":"2026-09-26T00:01:21.644Z","1.0.0":"2026-03-19T03:49:01.812Z","2.0.0":"2026-03-19T11:33:47.800Z","3.0.0":"2026-03-26T00:22:58.430Z","3.1.0":"2026-03-26T09:54:22.073Z","4.0.0":"2026-04-04T09:59:12.559Z","4.1.0":"2026-04-04T18:28:21.625Z","4.2.0":"2026-04-04T18:43:57.993Z","4.3.0":"2026-04-04T18:50:23.549Z","4.4.0":"2026-04-04T19:19:22.012Z","4.5.0":"2026-04-04T19:30:27.245Z","4.6.0":"2026-04-04T19:38:04.248Z","4.7.0":"2026-04-04T19:45:33.619Z","4.8.0":"2026-04-04T19:54:13.856Z","5.0.0":"2026-04-07T16:31:30.203Z","5.0.1":"2026-04-07T16:53:24.601Z","5.1.0":"2026-04-07T17:43:54.733Z","5.1.1":"2026-04-07T17:45:20.906Z","5.2.0":"2026-04-08T13:49:42.386Z","5.2.1":"2026-04-26T05:10:22.096Z","5.2.2":"2026-04-26T05:24:58.315Z","5.2.3":"2026-04-26T05:28:23.026Z","5.2.4":"2026-04-30T05:11:02.676Z","5.2.5":"2026-05-01T08:11:37.091Z","5.2.6":"2026-05-03T05:13:00.765Z","5.2.7":"2026-05-06T15:38:28.259Z","5.2.8":"2026-05-08T05:19:23.284Z","5.2.9":"2026-05-09T05:15:17.902Z","5.2.10":"2026-05-10T05:08:31.336Z","5.2.11":"2026-05-12T05:08:32.559Z","5.2.12":"2026-05-14T06:40:00.980Z","5.2.13":"2026-05-16T05:08:14.302Z","5.2.15":"2026-05-20T15:37:29.663Z","5.2.16":"2026-05-22T06:12:10.782Z","5.2.17":"2026-05-23T10:11:50.091Z","5.2.18":"2026-05-24T07:10:51.190Z","5.2.19":"2026-05-24T07:33:16.042Z","5.2.20":"2026-05-24T08:00:01.121Z","5.2.21":"2026-05-24T08:19:30.666Z","5.2.22":"2026-05-24T12:18:30.807Z","5.2.23":"2026-05-24T12:23:08.076Z","5.2.24":"2026-05-24T12:29:01.733Z","5.2.25":"2026-05-25T17:29:45.544Z","5.2.26":"2026-05-25T18:19:32.987Z","5.2.27":"2026-05-28T15:40:16.594Z","5.2.28":"2026-06-01T15:39:17.550Z","5.2.29":"2026-06-02T07:08:18.950Z","5.2.30":"2026-06-09T07:06:44.222Z","5.2.31":"2026-06-11T15:38:03.191Z","5.2.32":"2026-06-13T10:48:15.625Z","5.2.33":"2026-06-14T06:56:24.323Z","5.2.34":"2026-06-21T05:13:04.145Z","5.2.35":"2026-06-21T10:20:17.002Z","5.2.36":"2026-06-25T05:21:37.641Z","5.2.37":"2026-06-27T04:57:15.859Z","5.2.38":"2026-06-28T09:59:17.878Z","5.2.39":"2026-06-28T12:31:45.377Z","5.2.40":"2026-06-28T13:16:57.222Z","5.2.41":"2026-06-28T13:34:23.391Z","5.2.42":"2026-06-29T05:12:30.954Z","5.2.43":"2026-06-30T07:26:50.769Z","5.2.44":"2026-07-01T16:52:41.076Z","5.2.45":"2026-07-02T15:50:41.280Z","5.3.0":"2026-07-02T16:35:17.129Z","5.4.0":"2026-07-02T17:28:09.531Z","5.4.1":"2026-07-02T18:00:35.592Z","5.4.2":"2026-07-02T18:47:54.150Z","5.5.0":"2026-07-02T20:32:21.070Z","5.6.0":"2026-07-02T22:10:49.907Z","5.6.1":"2026-07-03T07:12:51.808Z","5.6.2":"2026-07-04T05:14:36.103Z","5.6.3":"2026-07-07T12:30:39.019Z","5.7.0":"2026-07-07T15:36:01.513Z","5.8.0":"2026-07-07T17:52:06.285Z","5.9.0":"2026-07-07T18:38:44.093Z","5.10.0":"2026-07-08T16:17:34.267Z","5.11.1":"2026-07-09T17:10:39.081Z","5.12.0":"2026-07-11T15:09:59.552Z","5.12.1":"2026-07-12T05:59:45.813Z","5.12.2":"2026-07-13T06:52:36.363Z","5.12.3":"2026-07-16T10:53:02.706Z","5.12.4":"2026-07-17T06:43:40.277Z","5.13.0":"2026-07-17T07:02:45.688Z","5.14.0":"2026-07-17T07:18:04.876Z","5.15.0":"2026-07-17T07:36:10.218Z","5.16.0":"2026-07-17T08:00:31.444Z","5.17.0":"2026-07-17T08:11:09.460Z","5.17.1":"2026-07-17T08:24:22.449Z","5.17.2":"2026-07-17T08:47:17.950Z","5.17.3":"2026-07-18T05:36:42.687Z","5.17.4":"2026-07-18T14:18:11.867Z","5.17.5":"2026-07-19T06:19:59.998Z","5.17.6":"2026-07-20T11:09:52.581Z","5.17.7":"2026-07-21T15:30:29.296Z","5.17.8":"2026-07-24T17:15:19.941Z","5.17.9":"2026-07-25T05:12:12.342Z","5.17.10":"2026-07-25T07:51:49.178Z","5.18.0":"2026-07-25T18:22:46.049Z","5.18.1":"2026-07-25T18:58:25.146Z","5.18.2":"2026-07-26T08:01:50.384Z","5.19.0":"2026-07-26T09:40:35.808Z","5.20.0":"2026-07-27T10:20:38.107Z","5.20.1":"2026-07-28T07:02:27.533Z","5.20.2":"2026-07-28T07:48:02.681Z","5.21.0":"2026-07-29T11:26:49.620Z","5.22.0":"2026-07-29T13:43:30.419Z","5.23.0":"2026-07-29T14:15:54.317Z","5.23.1":"2026-07-30T03:52:25.205Z","5.23.2":"2026-07-30T05:46:49.397Z","5.23.3":"2026-07-30T22:37:53.864Z","5.23.4":"2026-07-31T08:56:21.879Z","5.23.5":"2026-08-01T08:01:27.252Z","5.24.0":"2026-08-02T07:22:23.047Z","5.25.0":"2026-08-03T08:38:17.342Z","5.25.1":"2026-08-04T05:46:00.780Z","5.25.2":"2026-08-04T09:15:10.398Z","5.25.3":"2026-08-04T09:51:14.749Z","5.25.4":"2026-08-05T08:37:30.930Z","5.25.5":"2026-08-05T13:40:42.339Z","5.25.6":"2026-08-06T08:52:47.589Z","5.25.7":"2026-08-07T06:52:25.837Z","5.25.8":"2026-08-08T09:32:05.738Z","5.25.9":"2026-08-09T09:38:02.408Z","5.25.10":"2026-08-10T07:20:19.125Z","5.25.11":"2026-08-11T10:01:45.859Z","5.25.12":"2026-08-12T08:16:42.564Z","5.26.0":"2026-08-12T09:38:45.393Z","5.26.1":"2026-08-13T07:08:01.033Z","5.26.2":"2026-08-14T10:26:16.755Z","5.26.3":"2026-08-15T09:41:14.816Z","5.26.4":"2026-08-16T10:37:16.451Z","5.26.5":"2026-08-17T06:46:52.003Z","5.26.6":"2026-08-18T07:54:37.292Z","5.26.7":"2026-08-19T07:19:34.770Z","5.27.0":"2026-08-20T07:56:02.354Z","5.28.0":"2026-08-20T12:52:39.386Z","5.28.1":"2026-08-21T08:33:01.310Z","6.0.0":"2026-08-23T11:49:54.182Z","6.0.1":"2026-08-24T08:31:01.621Z","6.0.2":"2026-08-25T08:06:45.991Z","6.0.3":"2026-08-26T08:59:08.963Z","6.0.4":"2026-08-27T06:57:14.238Z","6.0.5":"2026-08-28T13:14:26.846Z","6.0.6":"2026-08-29T12:28:20.238Z","6.0.7":"2026-08-30T10:51:04.426Z","6.0.8":"2026-08-31T10:50:00.805Z","6.0.9":"2026-09-01T08:38:32.801Z","6.0.10":"2026-09-02T08:18:15.780Z","6.0.11":"2026-09-03T07:21:46.768Z","6.0.12":"2026-09-04T09:11:02.660Z","6.0.13":"2026-09-05T05:53:47.668Z","6.0.14":"2026-09-06T10:48:49.958Z","6.0.15":"2026-09-07T05:53:17.777Z","6.0.16":"2026-09-08T07:32:01.858Z","6.0.17":"2026-09-09T09:49:09.197Z","6.0.18":"2026-09-10T06:28:34.899Z","6.0.19":"2026-09-11T08:24:00.504Z","6.0.20":"2026-09-12T08:00:45.139Z","6.1.0":"2026-09-13T14:25:13.423Z","6.1.1":"2026-09-14T18:49:53.346Z","6.1.2":"2026-09-15T11:15:53.704Z","6.1.3":"2026-09-16T12:49:33.901Z","6.2.0":"2026-09-17T09:43:04.699Z","6.2.1":"2026-09-19T09:16:29.440Z","6.2.2":"2026-09-20T16:40:07.423Z","6.2.3":"2026-09-21T06:30:33.393Z","6.2.4":"2026-09-22T07:18:49.472Z","6.2.5":"2026-09-23T07:40:06.950Z","6.3.0":"2026-09-26T00:01:21.280Z"},"bugs":{"url":"https://github.com/homeofe/supply-chain-guard/issues"},"author":{"name":"Elvatis","email":"emre.kohler@elvatis.com"},"license":"Apache-2.0","homepage":"https://github.com/homeofe/supply-chain-guard#readme","keywords":["security","supply-chain","malware-detection","npm","pypi","cargo","golang","docker","terraform","glassworm","shai-hulud","scanner","cli","github-action","sarif","sbom","slsa","cyclonedx","devsecops","threat-intelligence","maven","gradle","nuget","rubygems","composer","vscode-extensions","browser-extensions","homebrew","helm","lockfile"],"repository":{"type":"git","url":"git+https://github.com/homeofe/supply-chain-guard.git"},"description":"Open-source supply-chain security scanner, local and offline. Matches known-malicious packages, extensions, plugins, providers, container images and CI actions in 15 ecosystems, including transitive lockfile dependencies at any depth, and detects GlassWor","maintainers":[{"name":"elvatis_com","email":"emre.kohler@elvatis.com"}],"readme":"# supply-chain-guard\n\nOpen-source supply-chain security scanner that runs locally and offline. It matches known-malicious packages, extensions, plugins, providers, container images and CI actions in 15 ecosystems, with tested matchers ready for more (see Ecosystem Coverage), reading manifests and lockfiles at any depth of a repository, including the transitive dependencies a lockfile pins; and it analyses what you install for malware behavior: GlassWorm, Vidar, Shai-Hulud, fake AI tool repos, account takeovers and 350+ threat indicators in all. It generates CycloneDX 1.6 SBOMs with real dependency inventories, grades SLSA provenance (parses and structurally validates in-toto/DSSE attestations), and correlates findings into attack-chain incidents. Supports EU Cyber Resilience Act SBOM and component-documentation work, and NIS2 supply chain risk-management measures.\n\n[![npm version](https://img.shields.io/npm/v/supply-chain-guard?logo=npm)](https://www.npmjs.com/package/supply-chain-guard)\n[![npm downloads](https://img.shields.io/npm/dw/supply-chain-guard?logo=npm&label=weekly%20downloads)](https://www.npmjs.com/package/supply-chain-guard)\n[![Node.js](https://img.shields.io/badge/Node.js-%3E%3D22-green?logo=node.js)](https://nodejs.org)\n[![TypeScript](https://img.shields.io/badge/TypeScript-Strict-blue?logo=typescript)](https://www.typescriptlang.org/)\n[![CI](https://img.shields.io/github/actions/workflow/status/homeofe/supply-chain-guard/ci.yml?branch=main&label=CI&logo=github)](https://github.com/homeofe/supply-chain-guard/actions/workflows/ci.yml)\n[![OpenSSF Scorecard](https://api.scorecard.dev/projects/github.com/homeofe/supply-chain-guard/badge)](https://scorecard.dev/viewer/?uri=github.com/homeofe/supply-chain-guard)\n[![OpenSSF Best Practices](https://www.bestpractices.dev/projects/14934/badge)](https://www.bestpractices.dev/projects/14934)\n[![AAHP Verify](https://github.com/homeofe/supply-chain-guard/actions/workflows/aahp-verify.yml/badge.svg)](https://github.com/homeofe/supply-chain-guard/actions/workflows/aahp-verify.yml)\n[![AAHP conformant](https://img.shields.io/badge/AAHP-conformant-5b47d6)](https://github.com/homeofe/AAHP)\n[![Last commit](https://img.shields.io/github/last-commit/homeofe/supply-chain-guard?logo=github)](https://github.com/homeofe/supply-chain-guard/commits/main)\n[![scanned by supply-chain-guard](https://github.com/homeofe/supply-chain-guard/actions/workflows/self-scan.yml/badge.svg?branch=main)](https://github.com/homeofe/supply-chain-guard/actions/workflows/self-scan.yml)\n[![License](https://img.shields.io/badge/License-Apache%202.0-blue.svg)](https://opensource.org/licenses/Apache-2.0)\n\n![supply-chain-guard scanning a malicious npm package: risk gauges, GlassWorm incident correlation, and a remediation plan](assets/demo.gif)\n\n## Start in 30 seconds\n\nScan a project. No account, no configuration, and the scan itself makes no\nnetwork request:\n\n```bash\nnpx supply-chain-guard scan .\n```\n\nIt exits `1` on a high finding or a scan that could not examine everything, and\n`2` on a critical finding, so it can gate a script as it is. To add the historical\npackage catalog, run `npx supply-chain-guard feed refresh` with network access in\nthe directory you scan from. The catalog is cached there in `.scg-cache` and\nbelongs to the installed version, so refresh again after an upgrade.\n\nGate every pull request:\n\n```yaml\n- uses: actions/checkout@v4\n- uses: homeofe/supply-chain-guard@v6.3.0\n```\n\nLet your AI coding agent check a package before it installs it (MCP):\n\n```bash\nnpm install -g supply-chain-guard\nclaude mcp add supply-chain-guard supply-chain-guard mcp\n```\n\nEvery release is published to npm from this repository's CI with a signed\n[SLSA provenance attestation](https://www.npmjs.com/package/supply-chain-guard),\nand the Action installs that exact version. Each GitHub Release also carries\nthe tarball with that provenance as a Sigstore bundle (`.sigstore.json`). To check\none yourself:\n\n```bash\ngh attestation verify supply-chain-guard-X.Y.Z.tgz \\\n  --bundle supply-chain-guard-X.Y.Z.tgz.sigstore.json \\\n  --repo homeofe/supply-chain-guard --digest-alg sha512\n```\n\nEverything else, from output\nformats to policies, is further down: [Quickstart](#quickstart),\n[GitHub Action](#github-action), [For AI Coding Agents (MCP)](#for-ai-coding-agents-mcp).\n\n## Contents\n\n- [Background](#background)\n- [What It Detects](#what-it-detects)\n- [Installation](#installation)\n- [Quickstart](#quickstart)\n- [Output Formats](#output-formats)\n- [CI Exit Code Control](#ci-exit-code-control)\n- [Filtering](#filtering)\n- [Internal Disclosure](#internal-disclosure)\n- [Policy Configuration](#policy-configuration-v44)\n- [Baseline Diffing](#baseline-diffing-v44)\n- [Example Output](#example-output)\n- [Ecosystem Coverage](#ecosystem-coverage)\n- [How It Compares](#how-it-compares)\n- [GitHub Action](#github-action)\n- [For AI Coding Agents (MCP)](#for-ai-coding-agents-mcp)\n- [Live Threat Feed](#live-threat-feed)\n- [Install Guard](#install-guard)\n- [Adding Custom Patterns](#adding-custom-patterns)\n- [Architecture](#architecture)\n- [EU Compliance (CRA / NIS2)](#eu-compliance-cra--nis2)\n- [Show that you scan](#show-that-you-scan)\n- [Contributing](#contributing)\n- [Changelog](#changelog)\n- [License](#license)\n\n## Background\n\nFor a deep dive into how GlassWorm infiltrates the software supply chain and the detection techniques behind this tool, read the blog post: [How GlassWorm Gets In and How We Locked It Out](https://blog.elvatis.com/how-glassworm-gets-in-and-how-we-locked-it-out/).\n\n## What It Detects\n\n### Known-Malicious Packages and Components\nPackage, extension, plugin and image identities are matched against the threat feed. This list is\ngenerated from the indicators that actually ship, so an ecosystem is only named as covered once there\nis something to match:\n\n<!-- ecosystem-list:begin (generated by scripts/generate-coverage-table.mjs; edit src/ecosystem-coverage.json) -->\n- Known-malicious indicators ship for 15 ecosystems: npm, PyPI, RubyGems, Composer (PHP), NuGet (.NET), Cargo (Rust), Go modules, Maven / Gradle / SBT / Bazel, Dart / Flutter (pub), Terraform / OpenTofu providers, Container images, GitHub Actions, VS Code / Open VSX extensions, Browser extensions (Chrome, Edge, Firefox) and JetBrains plugins.\n- Homebrew has a tested matcher and ships an indicator, but is not counted: its one indicator (the compromised Trivy tap release 0.69.4) needs a version, and only the legacy Brewfile.lock.json records one; current Homebrew writes no lock file, so a Brewfile alone cannot match it.\n- Matchers are built and tested, but no malicious package is publicly known yet, for 8 more: Swift Package Manager, CocoaPods, Hex (Elixir / Erlang), CRAN (R), Conan (C / C++), Terraform / OpenTofu modules, Helm charts and Ansible Galaxy. They report the day an indicator is published, through the importer or a curated entry.\n<!-- ecosystem-list:end -->\n\n- The files read per ecosystem are in [Ecosystem Coverage](#ecosystem-coverage).\n- Manifests and lockfiles are read wherever they sit in the tree, so a monorepo service or a .NET project\n  in `src/App/` is covered, and a lockfile's transitive dependencies are matched, not only direct ones.\n- A version pin fires only on the exact malicious release; a hijacked legitimate package is never blocked\n  by name. Registry-specific identities stay separate (Marketplace vs Open VSX, Chrome vs Edge, public vs\n  private registries), and a commit SHA or image digest matches under any repository name.\n\n### Malware Campaigns\n- GlassWorm campaign markers and Solana blockchain C2\n- Vidar/GhostSocks infostealers (April 2026 Claude Code leak campaign)\n- Shai-Hulud self-replicating npm worm\n- XZ Utils backdoor (CVE-2024-3094), SolarWinds SUNBURST, Codecov, ua-parser-js, coa/rc\n- Fake AI tool repos (Claude Code, Copilot, Cursor, ChatGPT, OpenClaw lures)\n\n### Code-Level Threats\n- Obfuscated execution: eval+atob, eval+Buffer.from, template literal eval, dynamic `import()`\n- Invisible Unicode, RTL override, SVG script injection, steganography\n- Shannon entropy analysis for encoded payloads\n- Proxy handler traps, WebAssembly from external sources\n- Scan-coverage transparency: files above the 5 MB content-scan limit are surfaced as `FILE_TOO_LARGE_SKIPPED` (info severity, never affects exit codes) instead of being silently skipped - padding a payload past the limit no longer hides it from the report\n\n### Supply Chain Attacks\n- Install hook deep analysis (secret harvesting, download-exec chains, binary blobs)\n- Levenshtein-based typosquatting detection against top 100 npm packages with known-safe whitelist\n- Dependency confusion and namespace squatting\n- Starjacking: in `npm <pkg>` mode, corroborates a package's claimed `repository` against the repo's own `package.json` and flags a repo borrowed from an unrelated popular project to inherit its stars/trust (conservative: monorepos, forks, related names, and unfetchable repos are not flagged)\n- Known-bad version blocklist (axios, ua-parser-js, coa, rc, event-stream, node-ipc, colors, faker)\n- Publishing anomaly detection (maintainer changes, version gaps, script additions)\n\n### Infrastructure & CI/CD\n- GitHub Actions: unpinned actions, secrets exfiltration, encoded payloads, curl piping\n- Agentic workflows (GitLost class): AI-agent steps and gh-aw `.github/workflows/*.md` that ingest untrusted issue/PR text, hold a cross-repo token, and can post publicly - the prompt-injection data-leak posture\n- Dockerfile / Containerfile hardening: curl pipe, base images on a moving channel tag or without a\n  digest, hardcoded secrets, SUID bits. These rules read Dockerfile instructions only\n  (see [docs/ARCHITECTURE.md](docs/ARCHITECTURE.md#base-image-pinning-decision-record)); known-malicious\n  images are matched separately in Dockerfiles and in every YAML `image:` value (Compose, Kubernetes,\n  workflow containers), see [Ecosystem Coverage](#ecosystem-coverage)\n- Terraform/IaC: inline scripts, external modules, hardcoded secrets; known-malicious providers and registry modules are matched as listed in [Ecosystem Coverage](#ecosystem-coverage)\n- Package manager configs (.npmrc, .yarnrc, pip.conf): HTTP registries, exposed tokens\n- Git hooks and submodule security\n\n### Repository Trust Signals\n- GitHub repo metadata analysis (account age, star-farming, single-commit repos)\n- Release artifact scanning (.exe, .7z, double extensions, LNK shortcuts, PE magic)\n- README lure detection (leaked/pirated/urgency language)\n\n### Prompt Injection Against AI Coding Agents (v5.2.19)\nDetects LLM-control tokens embedded in package READMEs that target downstream AI coding agents (Claude Code, Cursor, Copilot) reading the docs on behalf of a human developer. The example tokens below are HTML-escaped in the raw README so the patterns do not flag this documentation itself - they render normally in any markdown viewer:\n- `&lt;system-reminder&gt;` / `&lt;system-prompt&gt;` (Anthropic family)\n- `&lt;|im_start|&gt;` / `&lt;|im_end|&gt;` ChatML (OpenAI, Llama, Mistral, Qwen)\n- `&#91;INST&#93;` / `&#91;/INST&#93;` (Mistral, Llama instruction-tuned)\n- `&lt;|system|&gt;` / `&lt;|user|&gt;` / `&lt;|assistant|&gt;` (Phi, Gemma, Granite, generic role tokens)\n- Natural-language jailbreak phrasing (\"ignore previous instructions\")\n\n### Credential Detection\n- AWS access keys (AKIA/ASIA), GitHub tokens (ghp_/gho_), npm tokens\n- SSH private keys, generic API keys, PEM private keys\n\n### Internal Topology Disclosure\nNot credentials: the map of your network that a public repository hands out for free. Private and non-routable addresses (RFC1918, CGNAT, link-local, IPv6 ULA), internal-only hostnames (`.internal`, `.local`, `.lan`, `.corp`, `.home`, `.intranet`), clone URLs pointing at a forge that is not a known public one, developer home-directory paths, and internal service endpoints. Reported at `medium` (reconnaissance value, not compromise), with an optional deny-list for the names only your project knows. See [Internal Disclosure](#internal-disclosure).\n\n### Dead-Drop Resolver / C2 Detection\n- Steam Community profiles, Telegram channels, Pastebin, GitHub Gists\n- DNS TXT records, DNS-over-HTTPS, dynamic WebSocket URLs\n- Known C2 domains and IPs (from IOC blocklist)\n\n### Correlation Engine (v4.2)\nLinks individual findings into incident-level attack chains:\n- \"GlassWorm Campaign\" (marker + eval + exfiltration)\n- \"Vidar Stealer Infection\" (dead-drop + browser theft + dropper)\n- \"npm Account Takeover\" (maintainer change + install hooks + C2)\n- \"Fake Repository Malware\" (lure + exe release + new account)\n- 15+ correlation rules with confidence scoring\n\n### Trust Breakdown (v4.2)\nMulti-dimension trust scoring for package and repository inspections:\n- Publisher Trust (40%) / Code Quality (30%) / Dependency Trust (20%) / Release Process (10%) (all 4 dimensions populated for `npm`, `pypi`, `repo`, and remote `scan <github-url>` modes; local directory scans evaluate Code Quality and Dependency Trust with renormalised weights).\n\n## Installation\n\n**Requires Node.js 22 or newer.** Every release runs its complete test suite, and\ninstalls and executes its own packed tarball, on Node 22 and on Node 24, the current\nActive LTS. Full policy, including what the\npackage is published from and what the Action and container image run on:\n[`docs/node-support.md`](docs/node-support.md).\n\n```bash\nnpm install -g supply-chain-guard\n```\n\nOr use directly with npx:\n\n```bash\nnpx supply-chain-guard scan ./my-project\n```\n\n### pre-commit\n\nRun the scanner as a [pre-commit](https://pre-commit.com) hook (Python-ecosystem teams get the same gate without touching npm). Add this to your `.pre-commit-config.yaml`:\n\n```yaml\nrepos:\n  - repo: https://github.com/homeofe/supply-chain-guard\n    rev: v6.3.0\n    hooks:\n      - id: supply-chain-guard\n```\n\nThe scanner writes its risk history to `.scg-history/` in the scanned repo;\nit is not written when `--no-history` is set, which the hook now uses. For\nplain scans without that flag, add the folder to your `.gitignore`.\n\n**If a file in `.scg-history/` cannot be read, the scan says so and fails.** The\ntwo stores there, `risk-history.json` and `triage-decisions.json`, are the\nbaseline that trend, forecast and triage-governance rules compare against. A\nstore that is absent is a first scan and stays silent, which is the normal case\non a fresh checkout or a hosted runner. A store that exists but does not parse,\nbecause a scan was interrupted mid-write or the file was edited by hand, is lost\nevidence, and the two are deliberately not reported the same way: the scan emits\n`RISK_HISTORY_UNREADABLE` or `TRIAGE_STORE_UNREADABLE` at `high`, sets\n`partialScan: true`, and exits nonzero regardless of `--fail-on`, because an\nunusable baseline is an indeterminate result rather than a clean one. The\nunreadable file is left on disk rather than overwritten, so complete entries can\nstill be recovered from it, usually by closing the truncated JSON array by hand.\nDelete the file to start a new baseline once you have decided the old trend is\nexpendable. `--no-history` does not silence this: that flag stops the write, not\nthe read, so a corrupt store still degrades the verdict and is still reported.\n\nThe hook scans the repository root on every commit and fails on high or critical findings.\n\n### Docker\n\nRun the scanner without a Node toolchain via the official multi-arch image (linux/amd64, linux/arm64), published to GHCR on every release tag:\n\n```bash\ndocker run --rm -v ${PWD}:/scan ghcr.io/homeofe/supply-chain-guard:6.3.0 scan /scan\n```\n\n`${PWD}` works in bash, zsh, and PowerShell; in cmd.exe use `%cd%` instead.\n\n## Quickstart\n\n```bash\n# Scan a local directory\nsupply-chain-guard scan ./my-project\n\n# Scan a GitHub repo (includes trust signal analysis)\nsupply-chain-guard scan https://github.com/user/repo\n\n# Analyze a GitHub repo for trust signals + malware\nsupply-chain-guard repo https://github.com/user/repo\n\n# Scan an npm package (downloads without installing)\nsupply-chain-guard npm suspicious-package-name\n\n# Scan a PyPI package\nsupply-chain-guard pypi suspicious-package\n\n# Scan a VS Code extension\nsupply-chain-guard vscode publisher.extension-name\n\n# Scan a VS Code extension from the Open VSX registry (VSCodium etc.)\nsupply-chain-guard vscode publisher.extension --registry openvsx\n\n# Detect dependency confusion\nsupply-chain-guard confusion ./my-project\n\n# Scan an entire GitHub organization\nsupply-chain-guard org my-github-org\n\n# Scan only files changed since a commit (diff mode)\nsupply-chain-guard scan ./project --since HEAD~5\n\n# Opt in to public registry queries (requires network; sends package names to npm and PyPI)\nsupply-chain-guard scan ./project --check-registry\n\n# Expand every repeated text finding (text groups by rule and file by default)\nsupply-chain-guard scan ./project --all-findings\n\n# Opt into correlated two-tier gating and composite risk scoring\nsupply-chain-guard scan ./project --two-tier\n\n# Query resolved npm coordinates plus OSV, EPSS, CISA KEV and Scorecard\n# This requires network access and implies --two-tier\nsupply-chain-guard scan ./project --external-intel\n\n# Supply a previously obtained Scorecard value; also implies --two-tier\nsupply-chain-guard scan ./project --scorecard 8.4\n\n# Monitor a Solana C2 wallet\nsupply-chain-guard monitor <wallet-address> --once\n```\n\n## Output Formats\n\n```bash\nsupply-chain-guard scan ./project                # Human-readable text (default)\nsupply-chain-guard scan ./project --format json   # JSON (for CI/CD pipelines)\nsupply-chain-guard scan ./project --format html   # Standalone HTML report\nsupply-chain-guard scan ./project --format markdown # Markdown (for PR comments)\nsupply-chain-guard scan ./project --format sarif  # SARIF 2.1.0 (GitHub Code Scanning)\nsupply-chain-guard scan ./project --format sbom   # CycloneDX 1.6 SBOM with real dependency inventory\nsupply-chain-guard scan ./project --sbom-output sbom.json  # The same SBOM, written to a file instead of stdout\nsupply-chain-guard scan ./project --format badge   # Shields.io endpoint JSON\nsupply-chain-guard scan ./project --format gitlab  # GitLab Dependency Scanning report (security-report-schemas 15.2.4, see examples/gitlab-ci.yml)\nsupply-chain-guard scan ./project --format markdown --json-output canonical.json  # Same scan, human report plus canonical JSON\n```\n\n### Badge\n\nPublish the badge JSON from CI (gist or gh-pages), then point Shields at it:\n\nThe scan exits non-zero when it finds high/critical issues - exactly when the\nbadge MUST update to red. Neutralize the exit code on the generate step (or use\n`if: always()` on the publish step) so a bad scan never freezes the badge green:\n\n```yaml\n- name: Generate badge JSON\n  run: supply-chain-guard scan . --format badge > badge.json || true\n- name: Publish to gist\n  if: always()\n  run: gh api gists/YOUR_GIST_ID -X PATCH -F \"files[badge.json][content]=@badge.json\"\n  env:\n    GH_TOKEN: ${{ secrets.BADGE_GIST_TOKEN }}\n```\n\n```markdown\n![supply-chain-guard](https://img.shields.io/endpoint?url=https://gist.githubusercontent.com/YOUR_USER/YOUR_GIST_ID/raw/badge.json)\n```\n\n## CI Exit Code Control\n\n```bash\nsupply-chain-guard scan ./project --fail-on critical  # Fail only on critical\nsupply-chain-guard scan ./project --fail-on high       # Fail on high or above\nsupply-chain-guard scan ./project --fail-on info       # Fail on any finding\n```\n\n`--min-severity` may reduce report noise, but it cannot be stricter than the\nactive `--fail-on` gate because that would hide findings required for the exit\nverdict. Invalid combinations fail before scanning. Incomplete coverage also\nexits nonzero regardless of the severity threshold and is reported as\n`partialScan: true` in JSON.\n\n## Filtering\n\n```bash\nsupply-chain-guard scan ./project --min-severity high\nsupply-chain-guard scan ./project --exclude SOLANA_MAINNET,HEX_ARRAY\n```\n\n## Internal Disclosure\n\nSecret scanners answer one question: *did a credential get committed?* This family answers a different one: **did our internal topology get committed?**\n\nInternal hostnames, private LAN addresses, self-hosted forge URLs, developer home directories and private repository names are not credentials, so no secret scanner reports them. Together they are the reconnaissance map an attacker draws before touching anything: what exists, what it is called, where it listens, and who works on it. It leaks through the same boring channels every time. A copied clone command in a README. A `.env.example` that kept the real staging host. A comment with the path the author built from. A lockfile pointing at an internal registry. None of it is a secret, all of it is intelligence, and it stays in git history long after the file is fixed.\n\nThe rules are **shape-based**, so they work on a repository whose owner has configured nothing at all. You never have to write down what your infrastructure is called in order to be protected from publishing it.\n\n### What it catches\n\n| Rule | Severity | Shape |\n|---|---|---|\n| `INTERNAL_PRIVATE_IP` | medium | RFC1918 (`10.0.0.0/8`, `172.16.0.0/12`, `192.168.0.0/16`), CGNAT (`100.64.0.0/10`), link-local (`169.254.0.0/16`) |\n| `INTERNAL_PRIVATE_IPV6` | medium | IPv6 Unique Local Addresses (`fc00::/7`) |\n| `INTERNAL_HOSTNAME` | medium | Hostnames in an internal-only TLD: `.internal`, `.local`, `.lan`, `.corp`, `.home`, `.intranet` |\n| `INTERNAL_SERVICE_ENDPOINT` | medium | `http(s)://HOST:PORT` where HOST is private or internal |\n| `INTERNAL_GIT_REMOTE` | medium | `ssh://git@<host>:<port>/<path>` and scp-style `git@<host>:<path>` where the host is not a known public forge |\n| `INTERNAL_DEV_PATH` | medium | `C:\\Users\\<name>\\`, `/home/<name>/`, `/Users/<name>/` in committed code or docs. `/Users/` is matched case-sensitively, because `/users/` is a REST route |\n| `INTERNAL_SINGLE_LABEL_URL` | low | A URL whose host has no domain at all, so it only resolves through internal DNS or a hosts file |\n| `INTERNAL_DENYLIST_MATCH` | medium | A term your project configured (see below). Off unless configured |\n| `INTERNAL_DISCLOSURE_TRUNCATED` | info | A limit stopped this family short on one file (see [Bounded cost](#bounded-cost)). Never silent about a gap |\n\n**Severity follows the host, not the rule.** A host with no domain part is the weakest signal in the family whichever rule reports it, so a dotless `payments` host with a port is `low`, exactly like the same host without one. Only a dotted internal name or a private address makes an endpoint `medium`.\n\n`INTERNAL_GIT_REMOTE` is the one worth pointing at: it finds a self-hosted forge **without anyone having to name it**. Any clone URL that is not github.com, gitlab.com, bitbucket.org, codeberg.org, git.sr.ht and the other well-known public hosts is, by shape alone, a forge somebody runs privately.\n\n### Severity is deliberately not inflated\n\nTopology is reconnaissance value, not compromise, so the family reports `medium` and `low`. `high` and `critical` stay reserved for credential-shaped findings, which the existing rules already own.\n\nPractically: the default gate exits non-zero on `critical` and `high` only, so **upgrading cannot turn a passing build red**. `--fail-on high` and `--fail-on critical` are equally unaffected. Two things do change: the risk **score** rises (each medium adds points), and a pipeline that runs `--fail-on medium` or lower will see the new findings. If you would rather not see them at all, they respect every existing control:\n\n```yaml\nrules:\n  disable:\n    INTERNAL_PRIVATE_IP: RFC1918 addresses are expected in this repository's fixtures\n    INTERNAL_HOSTNAME: internal names are already covered by a separate review\n```\n\nThe parser reads block style only; a flow sequence on one line\n(`disable: [A, B]`) is reported as `POLICY_UNKNOWN_KEY` and disables nothing.\n\n### False-positive controls\n\nA rule that screams on every README gets switched off, and a switched-off rule protects nothing. Three independent layers keep this quiet.\n\n**1. The reserved documentation space never fires.** Anything written the way the RFCs intend is invisible to these rules:\n\n- addresses from RFC5737: `192.0.2.0/24`, `198.51.100.0/24`, `203.0.113.0/24`\n- names from RFC2606: `example.com`, `example.org`, `example.net`, the `.example` TLD, `.invalid`, `.test`\n- loopback and the unspecified address, `localhost` URLs\n- placeholder and CI account names in paths: `runner`, `vscode`, `ubuntu`, `jenkins`, `you`, `dev`, `user`, `Public` and more\n- container and compose service aliases in single-label URLs: `db`, `redis`, `api`, `minio`, `nginx`, and the `unix` / `npipe` pseudo-hosts that mean \"a UNIX domain socket, not a machine\"\n- a CIDR range such as `10.0.0.0/16` is a subnet layout, not a host, so it is not reported (a `/32` host route is)\n- **universal infrastructure constants**, which are the same address in every installation on earth and therefore describe nobody's topology: the cloud metadata endpoint `169.254.169.254` (and the ECS `169.254.170.2`, Amazon Time Sync `169.254.169.123`, Alibaba `100.100.100.200`), the Kubernetes defaults `10.96.0.1` and `10.96.0.10` and the k3s `10.43.0.1` / `10.43.0.10`, the default service and pod CIDRs (`10.96.0.0/12`, `10.244.0.0/16`, `10.42.0.0/16`), the Docker bridge gateway `172.17.0.1`, and the Docker Desktop names `host.docker.internal` and friends. A real address inside the same ranges is still reported.\n\n**2. A match has to sit where its rule can mean what it claims.**\n\n- An internal-only TLD has to be the **last** label of the name, so `config.internal.timeout`, `com.acme.internal.util` and `settings.local.json` are never hosts.\n- A name preceded by a path separator is a **file**, not a host: `./config.local`, `src/config.local` and `../lib/settings.local` are module specifiers. `https://db.example.corp/`, `//registry.svc.example.corp/` and `git@forge.internal.example:...` still are hosts.\n- A name followed by `(` is a **method call**: `res.local(name, val)` in a changelog is not a machine.\n- In programming-language sources a bare dotted name is only reported inside a string literal, a comment or a URL, because `config.internal.timeout` and `state.local.value` are property accesses. Data and config files (`.yml`, `.json`, `.toml`, `.env`, Dockerfile, lockfiles) carry unquoted values, so no quotes are required there.\n- `/Users/` is matched **case-sensitively** and `:id`, `{id}`, `<id>` and `${user}` are rejected after the account segment, so `app.get(\"/users/:id\")`, `\"/users/{id}\"` and `app.get(\"/users/profile/edit\")` are routes, not macOS home directories. A Windows path keeps both spellings, because `C:\\users\\` is unambiguous.\n\n**3. The surface decides which rules stay armed.**\n\n| Surface | Rules that still fire |\n|---|---|\n| Source files (`.ts`, `.py`, `.tf`, `.yml`, Dockerfile, `.npmrc`, lockfiles) | all of them |\n| Documentation prose and fenced code blocks: `.md` / `.rst` / `.txt`, anything under `docs/` | everything except the single-label URL |\n| Markdown inline code spans, and fenced blocks tagged ```` ```text ```` / ```` ```plaintext ```` | hostname, endpoint, clone URL |\n| Files that exist to BE an example: `examples/`, `samples/`, `fixtures/`, `testdata/`, `*.example.*` / `*.sample.*` / `*.template.*` | hostname, endpoint, clone URL |\n| Test, spec, mock and fixture files and directories (`test/`, `tests/`, `spec/`, `e2e/`, `__tests__/`, `__mocks__/`, `*.test.*`), minified and bundled output | none |\n\nThe reasoning changed here, deliberately. Documentation used to be excluded wholesale, which silenced precisely the case this family exists for: **a private address or a developer path inside a README is one of the most common ways internal topology reaches a public repository**, and a `/home/<name>/` in a pasted stack trace is a real leak, not a teaching aid. The reserved namespace above is what protects a writer who follows the RFCs, and it works on every surface. What stays excluded is what measurement showed to be noise rather than signal: inline code spans (on the sample used to tune this, eight findings, all of them API signatures or documented examples), placeholder fences, and files whose whole purpose is to show a shape.\n\nTwo things are reported on purpose even though they can be examples. Kubernetes in-cluster names (`<service>.<namespace>.svc.cluster.local`) name your service inventory. And an address or path inside a **code comment** (a JSDoc `@example` block, say) is reported, because a comment is the single most common place a real host gets written down and nothing distinguishes an illustrative address from a real one there. Use RFC5737 addresses in code examples, or suppress by path.\n\n<a id=\"bounded-cost\"></a>\n### Bounded cost\n\nA generated bundle is one 800 KB line, and a rule family that takes minutes on it is a rule family that gets switched off. Four limits keep the cost flat, and none of them is silent:\n\n- line offsets are computed **once per file** and binary-searched, and each line's quoting and comment structure is computed **once per line** rather than once per match\n- a line longer than **2000 characters** is skipped, the way an oversized file is skipped by `FILE_TOO_LARGE_SKIPPED`\n- at most **25 findings per pattern** and **100 per file**. Two rules\n  (`INTERNAL_DEV_PATH` and `INTERNAL_GIT_REMOTE`) are each written as two\n  patterns, so those can reach 50 from a single file. When the per-file cap\n  drops findings it keeps the most severe ones.\n- at most **20000 candidate matches per rule per file**, which bounds the case where nearly everything is filtered out and so produces no findings to count\n\nWhenever a limit is reached, the file gets one `INTERNAL_DISCLOSURE_TRUNCATED` finding at `info` severity naming the limit. A scanner that quietly stopped looking is indistinguishable from a repository with nothing to find, and that is not a trade this tool makes.\n\nOn top of that, everything else already in this tool applies: `suppress` with a `path:` glob, `ignore:` globs, `--exclude`, `--min-severity`, and inline `// scg-ignore-next-line INTERNAL_HOSTNAME reason`.\n\n### The deny-list, and its paradox\n\nShape rules cannot know that `sample-service` is one of your private repositories. A deny-list can. But **a list of your internal hostnames committed to a public repository is exactly the leak you were trying to prevent**, so there are three ways to configure one and only one of them puts plaintext in the repo.\n\n```yaml\n# yaml-language-server: $schema=./node_modules/supply-chain-guard/policy-schema.json\n\n# Whether the downloadable historical catalog must be present for a scan to\n# count as complete. \"optional\" (the default) reports THREAT_FEED_CATALOG_MISSING\n# and carries on; \"required\" raises it to critical.\ncatalog: optional\n\ninternalDisclosure:\n  # (a) HASHED. Publishable: the digest hides the term from a reader and from\n  #     grep. It is not a vault - see \"What hashing is worth\" below.\n  #     Generate with: supply-chain-guard internal-hash forge.internal.example\n  hashedTerms:\n    # sha256(\"forge.internal.example\") and sha256(\"acme/sample-service\"),\n    # so you can verify the recipe below against these two lines.\n    - 113fbef8cb1afd8d755cfa3c5b954244973c1b4182824c64755235de60a3d106\n    - 479ec322598b9047aaac200d2c1c2d5ab9658ce50ef7e60dc1081741f037d7d3\n\n  # (b) EXTERNAL. Full regex/plaintext patterns that must never be published.\n  #     Gitignore this file, or provision it on the runner. Matches are\n  #     reported REDACTED, so the report cannot leak it either.\n  externalFile: .scg-internal-terms.local\n\n  # (c) PLAINTEXT. For a private repository scanning itself, or terms that\n  #     are not sensitive. Literals, or /regex/flags.\n  patterns:\n    - sample-service\n    - /build-\\d{2}\\.corp/\n```\n\n**Hashing recipe.** Normalisation is `trim`, then `lowercase`. Then sha256, lowercase hex. That is the whole rule, so any tool can reproduce it:\n\n```bash\n# Bundled helper (prints only the digest, so nothing sensitive rides along)\nsupply-chain-guard internal-hash forge.internal.example\n\n# The same digest, without this tool\nprintf '%s' \"forge.internal.example\" | tr 'A-Z' 'a-z' | sha256sum\n```\n\n**What hashing is worth, honestly.**\n\n*As a matcher* it is exact-token matching, nothing more. A token is a maximal run of letters, digits, `.`, `_` and `-` (so `https://forge.internal.example/x` yields `forge.internal.example`), plus an `org/repo` pair and a `.git` suffix stripped, all lowercased. A hashed entry for `forge.internal.example` therefore matches that host but not `sub.forge.internal.example`, and there is no way around it: a scanner that could match substrings of a hash would be a scanner that could recover the term. When you need substring or regex power, use `externalFile` (b).\n\n*As a secret* it buys less than \"hashed\" suggests, and it is worth saying plainly. An unsalted, single-round sha256 of a low-entropy value is **dictionary-attackable**: hostnames come from a small, guessable space (a short site or service word, a two-digit index, one of a handful of internal TLDs), so anyone with your repository can hash candidate names until one matches. What a digest genuinely buys is that the term is not sitting in the file to be read, copied or grepped, and that it does not travel into a report, a log or a screenshot. That is real, and it is not the same as being unrecoverable.\n\n*If you need the stronger claim,* salt it with a value that lives outside the repository:\n\n```bash\nexport SCG_INTERNAL_HASH_SALT=\"$(openssl rand -hex 16)\"    # store it wherever your CI secrets live\nsupply-chain-guard internal-hash forge.internal.example    # generates a salted digest\n```\n\n```yaml\ninternalDisclosure:\n  hashSalted: true          # says the digests below are salted\n  hashedTerms:\n    - <salted digest>\n```\n\nThe salt has to be held outside the repository to be worth anything: a salt committed next to the digests is hashed by the same reader who reads them, which is why there is no config key for the salt itself. `hashSalted: true` is what keeps this fail-visible - a scan that runs without the salt matches nothing, which looks exactly like a clean repository, so the declaration turns that silence into an `INTERNAL_DENYLIST_UNAVAILABLE` finding instead.\n\n**An environment variable** does the same thing as `externalFile` without touching the committed config at all:\n\n```bash\nSCG_INTERNAL_DISCLOSURE_FILE=~/.config/scg/internal-terms supply-chain-guard scan .\n```\n\nThe external file is one entry per line, `#` for comments, `sha256:<digest>` for a hashed entry, `/pattern/flags` for a regex, anything else is a case-insensitive literal. If the file is configured but absent (a shared CI runner that never received it), you get an `INTERNAL_DENYLIST_UNAVAILABLE` finding at `info` severity rather than silence: a deny-list that quietly stopped running looks exactly like a repository that is clean. An entry that cannot be compiled is reported the same way (`INTERNAL_DENYLIST_INVALID_ENTRY`, medium). Neither finding ever prints the entry, and the environment variable is named but its value is not, because a path can itself contain an account name.\n\n**The two sources are not equally trusted, and the difference is deliberate.** `SCG_INTERNAL_DISCLOSURE_FILE` is set by whoever runs the scan, so it may name any path on the machine and carry any pattern. `internalDisclosure.externalFile` and `internalDisclosure.patterns` live in the committed policy file, which travels inside the repository being scanned, and scanning a repository you do not own is the ordinary case for this tool. Entries from there are therefore bounded:\n\n- `externalFile` must stay inside the scanned directory. An absolute path is refused, a relative path that climbs out with `..` is refused, and so is one that leaves through a symbolic link. The file is not opened, so nothing about a path outside the tree reaches the report. The bound is the scanned directory and nothing narrower: a path that stays inside it is still read, `.git/config` included, so a committed `externalFile` can still point at whatever your runner wrote into the workspace. Matches from it stay redacted.\n- A regular expression from `patterns`, **or from an `externalFile` that is inside the tree**, is capped at 200 characters and refused when it quantifies a group that already contains a variable quantifier (`(a+)+`, `(a?)*`, and the like). That shape can take exponential time to report no match, so one committed line would otherwise occupy a runner until the workflow times out.\n- Whatever survives those checks runs under a wall-clock budget for the whole scan. On overrun the file reports `INTERNAL_DISCLOSURE_TRUNCATED` rather than running on.\n\nA refusal is an `INTERNAL_DENYLIST_REFUSED` finding at `medium` severity, and like every other coverage finding it marks the scan partial rather than passing quietly. In the published Action a partial scan exits 1 on its own, independently of `fail-on`. None of this applies to the environment-variable source.\n\n**Two limits of the shape check, both worth knowing before you upgrade.**\n\nIt refuses more than it has to, and the shape it most often refuses is the ordinary one. A chained label group is how an internal hostname is normally written, and it is rejected even though it is linear in practice:\n\n```yaml\ninternalDisclosure:\n  patterns:\n    - /(?:[a-z0-9-]+\\.)+corp\\.example/   # REFUSED: quantified group holding \"+\"\n    - /[a-z0-9.-]+\\.corp\\.example/       # accepted, and matches the same hosts\n```\n\nIf you have the first form today, in `patterns` or in your own gitignored `externalFile`, rewrite it before you upgrade. Left as it is, the term stops being looked for, the scan becomes partial, and the Action exits 1.\n\nIt also refuses less than it has to, so an accepted pattern is not a promise about time. The check reads the source text, which cannot see ambiguity that comes from overlapping alternation, so `/(a|a)+$/` and `/(a|ab)+$/` are accepted and are still catastrophic, and the wall-clock budget cannot interrupt a match that is already running. Availability from a committed pattern is narrowed here, not closed; the remaining case is tracked on [issue 169](https://github.com/homeofe/supply-chain-guard/issues/169).\n\n**One more note on the paradox.** `allowlist.domains` also answers `INTERNAL_HOSTNAME`, `INTERNAL_SERVICE_ENDPOINT` and `INTERNAL_GIT_REMOTE` for a given host, which is convenient and publishes the host name. If that is not acceptable, suppress by path instead, which names nothing:\n\n```yaml\nsuppress:\n  - rule: INTERNAL_HOSTNAME\n    reason: vendored upstream config, reviewed\n    path: vendor/**\n```\n\n## Policy Configuration (v4.4)\n\nCreate `.supply-chain-guard.yml` in your project root to customize behavior:\n\n```yaml\nrules:\n  # Every disabled rule needs a written reason, the same bar `suppress` has met\n  # since v5.3. The bare list form (`- HEX_ARRAY`) still disables the rule and is\n  # reported as POLICY_DISABLE_NO_REASON.\n  disable:\n    HEX_ARRAY: minified vendor bundles in this repository, reviewed 2026-08\n    CHARCODE_OBFUSCATION: same bundles, same review\n  severityOverrides:\n    GHA_UNPINNED_ACTION: medium\n\nallowlist:\n  packages:\n    - internal-utils\n  domains:\n    # Suppresses THREAT_INTEL_MATCH / IOC_KNOWN_C2_DOMAIN findings whose matched\n    # host is this domain or a subdomain of it.\n    - company.example.internal\n  githubOrgs:\n    # Trusted action publishers. Suppresses the ownership-trust findings\n    # (GHA_THIRD_PARTY_ACTION, GHA_TAG_NOT_SHA) for actions owned by these\n    # orgs. Pinning and known-malicious-SHA rules stay armed: trusting an org\n    # says who publishes the code, not that every version of it is safe.\n    - my-org\n\n# Skip files matched by these path globs (** / * / ?) during the scan. These\n# files are never opened, so nothing about them reaches the report except the\n# policy block below. Each glob needs a written reason; the bare list form\n# (`- vendor/**`) still skips the path and is reported as POLICY_IGNORE_NO_REASON.\nignore:\n  \"vendor/**\": third-party code, tracked by the upstream project's own scanning\n  \"**/*.min.js\": build output, scanned at source instead\n\nsuppress:\n  - rule: RELEASE_EXE_ARTIFACT\n    reason: Legitimate Windows installer\n  # Optional path glob: suppress a rule only under a matching path.\n  - rule: EVAL_ATOB\n    reason: Vendored third-party bundle, reviewed\n    path: vendor/**\n\nbaseline:\n  file: .scg-baseline.json\n```\n\nFindings can also be suppressed inline with a comment on the line directly\nabove them: `// scg-ignore-next-line RULE reason` (JS/TS) or\n`# scg-ignore-next-line RULE` (Python/YAML/shell).\n\n### Where the policy is read from, and what that means on a pull request\n\nThe policy file is read **from the directory being scanned**, and from nowhere\nelse. There is no flag, environment variable or Action input that points the\nscanner at a policy outside the scan target.\n\nOn a `pull_request` event the checkout materialises the **head of the proposing\nbranch**, so the policy that governs the scan is the one on the branch under\nreview, not the one on your default branch. A change that adds\n`.supply-chain-guard.yml` alongside the code it excuses is applying its own\npolicy to itself. Anyone who can push a branch can therefore narrow the scan of\nthat branch.\n\nThat is a property of reading policy from the tree, and it is stated here rather\nthan left to be discovered. What it is **not** is silent:\n\n- Every narrowing is named in the report, in **all nine output formats**,\n  including the markdown pull request comment the Action posts by default.\n  A scan narrowed by policy can no longer be mistaken for a clean scan in any\n  format, including `ignore:`, which removes files before any rule opens them\n  and used to leave no trace anywhere.\n- A narrowing declared without a written reason is reported as a finding\n  (`POLICY_DISABLE_NO_REASON`, `POLICY_IGNORE_NO_REASON`,\n  `POLICY_SUPPRESSION_NO_REASON`), so an undocumented exclusion costs a line in\n  the report rather than nothing.\n\nIf your threat model includes an untrusted proposer, the controls that actually\nhold are outside this tool: require review on `.supply-chain-guard.yml` through\n`CODEOWNERS`, or scan a base-ref checkout in a separate job. Treat a policy file\nin a pull request diff as a change to your security gate, because it is one.\n\n## Baseline Diffing (v4.4)\n\nOnly report NEW findings (ignore known baseline):\n\n```bash\n# Save current findings as baseline\nsupply-chain-guard scan ./project --save-baseline .scg-baseline.json\n\n# On subsequent scans, only show new findings\nsupply-chain-guard scan ./project --baseline .scg-baseline.json\n```\n\n## Example Output\n\n```\n╔══════════════════════════════════════════════════════════════════════════════╗\n║  supply-chain-guard                                                  v5.1.0 ║\n╚══════════════════════════════════════════════════════════════════════════════╝\n\n  Target         ./suspicious-package\n  Type           directory  ·  18 / 18 files scanned\n  Duration       142 ms\n  Time           2026-04-07T12:00:00.000Z\n\n┌────────────────────────────── DETECTED RISK ───────────────────────────────┐\n│                                                                              │\n│   83 / 100   █████████████████████████████████░░░░░   CRITICAL             │\n│                                                                              │\n└──────────────────────────────────────────────────────────────────────────────┘\n\n┌──────────────────────────── FINDINGS SUMMARY ───────────────────────────────┐\n│  CRITICAL      3  ████████████████████████████████                          │\n│  HIGH          1  ██████████                                                 │\n│  MEDIUM        0  ────────────────────────────────                           │\n│  LOW           0  ────────────────────────────────                           │\n│  INFO          0  ────────────────────────────────                           │\n└──────────────────────────────────────────────────────────────────────────────┘\n\n┌──────────────────────────────── FINDINGS ───────────────────────────────────┐\n│                                                                              │\n│  [CRITICAL]  DEAD_DROP_STEAM                                                │\n│              Steam Community profile URL used as dead-drop C2 resolver      │\n│              src/config.js:12                                                │\n│              match  https://steamcommunity[.]com/profiles/76561198...       │\n│              fix    Remove external URL resolution; use static configuration │\n│                                                                              │\n│ ············································································· │\n│                                                                              │\n│  [CRITICAL]  VIDAR_BROWSER_THEFT                                            │\n│              Browser credential file access (infostealer pattern)           │\n│              src/steal.js:45                                                 │\n│              match  AppData[...]Google[...]Chrome[...]Login Data             │\n│              fix    Never access browser credential stores                   │\n│                                                                              │\n│ ············································································· │\n│                                                                              │\n│  [CRITICAL]  DROPPER_TEMP_EXEC                                              │\n│              Dropper: file written and executed from temp directory          │\n│              src/loader.js:23                                                │\n│              match  saveFile(tmpdir, payload); exe‹c›(tmpPath)              │\n│              fix    Remove dropper logic; audit all exec() call sites        │\n│                                                                              │\n└──────────────────────────────────────────────────────────────────────────────┘\n\n┌─────────────────────────── TRUST BREAKDOWN ─────────────────────────────────┐\n│  Publisher       ██████░░░░░░░░░░░░░░░░░░░░░░░░░░░░  20/100               │\n│  Code            █████████░░░░░░░░░░░░░░░░░░░░░░░░░  30/100               │\n│  Dependencies    ████████████████████████████████████ 100/100              │\n│  Release         ██████████████████████████░░░░░░░░░  80/100               │\n│────────────────────────────────────────────────────────────────────────────│\n│  Assessed        █████████████░░░░░░░░░░░░░░░░░░░░░░  48/100               │\n│  4/4 trust dimensions assessed                                             │\n└──────────────────────────────────────────────────────────────────────────────┘\n\n┌──────────────────────────── CORRELATED INCIDENTS ───────────────────────────┐\n│                                                                              │\n│  [CRITICAL]  Vidar Stealer Infection  95% confidence                        │\n│  Multiple infostealer indicators: dead-drop resolvers for C2,               │\n│  browser credential theft, and crypto wallet targeting.                     │\n│  Indicators: DEAD_DROP_STEAM, VIDAR_BROWSER_THEFT, DROPPER_TEMP_EXEC       │\n│                                                                              │\n└──────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Ecosystem Coverage\n\nTwo different claims live here, and they are proven differently.\n\n**Known-malicious identity matching.** For every ecosystem below, a directory scan reads the listed files\nat the scan root and at any depth below it, extracts the package, extension, plugin, provider, image or\naction identities, and matches them against the threat feed: the bundled indicators, and the downloadable\ncatalog after `feed refresh`. A version pin fires only on the exact malicious release; a range or a\nconstraint in a manifest leaves the version unknown, so only a whole-name entry can match there.\n\nThis table is generated from [`src/ecosystem-coverage.json`](src/ecosystem-coverage.json) and checked by\nthe build (`check:coverage`); it is not written by hand. Every row is proven by\n[`coverage-matrix.test.ts`](src/__tests__/coverage-matrix.test.ts), which puts an indicator into each\nlisted file format, at the scan root and one directory down, runs a real scan and requires the rule to\nreport it exactly once. A format listed here without such a test fails the test suite. \"Indicators shipped\"\nsays whether any indicator exists today; \"none yet (matcher ready)\" means the matcher is proven but no\nmalicious package is known in that ecosystem yet, and the importer or a curated entry will fill it.\n\n<!-- ecosystem-coverage:begin (generated by scripts/generate-coverage-table.mjs; edit src/ecosystem-coverage.json) -->\n| Ecosystem | Files read | Rule | Indicators shipped | Imported automatically from |\n| --- | --- | --- | --- | --- |\n| npm | `package.json`, `package-lock.json`, `yarn.lock`, `pnpm-lock.yaml`, `bun.lock` | `MALICIOUS_DEPENDENCY`, `LOCKFILE_MALICIOUS_VERSION`, `LOCKFILE_MALICIOUS_PACKAGE` | bundle + catalog | GitHub Advisory Database, OpenSSF / OSV |\n| PyPI | `requirements.txt`, `pyproject.toml`, `poetry.lock`, `uv.lock`, `Pipfile.lock` | `PYTHON_MALICIOUS_PACKAGE` | bundle + catalog | GitHub Advisory Database, OpenSSF / OSV |\n| RubyGems | `Gemfile`, `Gemfile.lock` | `RUBY_MALICIOUS_GEM` | bundle + catalog | GitHub Advisory Database, OpenSSF / OSV |\n| Composer (PHP) | `composer.json`, `composer.lock` | `COMPOSER_MALICIOUS_PACKAGE` | bundle + catalog | GitHub Advisory Database, OpenSSF / OSV |\n| NuGet (.NET) | `packages.lock.json`, `*.csproj`, `packages.config` | `NUGET_MALICIOUS_PACKAGE` | bundle + catalog | GitHub Advisory Database, OpenSSF / OSV |\n| Cargo (Rust) | `Cargo.toml`, `Cargo.lock` | `CARGO_MALICIOUS_CRATE` | bundle + catalog | GitHub Advisory Database, OpenSSF / OSV |\n| Go modules | `go.mod`, `go.sum` | `GO_MALICIOUS_MODULE` | bundle | GitHub Advisory Database, OpenSSF / OSV |\n| Maven / Gradle / SBT / Bazel | `pom.xml`, `gradle.lockfile`, `build.gradle`, `build.gradle.kts`, `libs.versions.toml`, `build.sbt`, `maven_install.json` | `MAVEN_MALICIOUS_PACKAGE` | bundle + catalog | GitHub Advisory Database, OpenSSF / OSV |\n| Dart / Flutter (pub) | `pubspec.lock`, `pubspec.yaml` | `PUB_MALICIOUS_PACKAGE` | bundle | GitHub Advisory Database, OSV |\n| Swift Package Manager | `Package.resolved`, `Package.swift` | `SWIFT_MALICIOUS_PACKAGE` | none yet (matcher ready) | GitHub Advisory Database, OSV (SwiftURL) |\n| CocoaPods | `Podfile.lock`, `Podfile` | `COCOAPODS_MALICIOUS_POD` | none yet (matcher ready) | curated only |\n| Hex (Elixir / Erlang) | `mix.lock`, `mix.exs` | `HEX_MALICIOUS_PACKAGE` | none yet (matcher ready) | GitHub Advisory Database, OSV |\n| CRAN (R) | `renv.lock`, `DESCRIPTION` | `CRAN_MALICIOUS_PACKAGE` | none yet (matcher ready) | OSV |\n| Conan (C / C++) | `conan.lock`, `conanfile.txt`, `conanfile.py` | `CONAN_MALICIOUS_PACKAGE` | none yet (matcher ready) | curated only |\n| Terraform / OpenTofu providers | `*.tf (required_providers)`, `.terraform.lock.hcl` | `TERRAFORM_MALICIOUS_PROVIDER` | bundle | curated only |\n| Terraform / OpenTofu modules | `*.tf (module)`, `.terraform/modules/modules.json` | `TERRAFORM_MALICIOUS_MODULE` | none yet (matcher ready) | curated only |\n| Helm charts | `Chart.yaml`, `Chart.lock` | `HELM_MALICIOUS_CHART` | none yet (matcher ready) | curated only |\n| Ansible Galaxy | `requirements.yml`, `galaxy.yml` | `ANSIBLE_MALICIOUS_CONTENT` | none yet (matcher ready) | curated only |\n| Container images | `Dockerfile`, `docker-compose.yml`, `Kubernetes manifest (image:)` | `DOCKER_MALICIOUS_IMAGE` | bundle | curated only |\n| GitHub Actions | `.github/workflows/*.yml`, `action.yml (composite)` | `GHA_KNOWN_MALICIOUS_SHA` | bundle | curated only |\n| Homebrew | `Brewfile`, `Brewfile.lock.json` | `HOMEBREW_MALICIOUS_PACKAGE` | bundle (legacy format only) | curated only |\n| VS Code / Open VSX extensions | `.vscode/extensions.json`, `devcontainer.json`, `installed extension package.json` | `VSCODE_MALICIOUS_EXTENSION` | bundle + catalog | OpenSSF / OSV (VSCode) |\n| Browser extensions (Chrome, Edge, Firefox) | `Chromium policy JSON`, `Firefox policies.json`, `installed Chromium extension`, `Firefox extension manifest` | `BROWSER_MALICIOUS_EXTENSION` | bundle | curated only |\n| JetBrains plugins | `.idea/externalDependencies.xml`, `META-INF/plugin.xml` | `JETBRAINS_MALICIOUS_PLUGIN` | bundle | curated only |\n<!-- ecosystem-coverage:end -->\n\n**Behavior and hardening analysis.** Independent of the feed, these read what a package or repository\nactually does:\n\n| Target | Command | What It Scans |\n|--------|---------|---------------|\n| npm package | `npm <pkg>`, `scan` | package.json install scripts and tarball contents: install-hook chains, obfuscation, exfiltration |\n| PyPI package | `pypi <pkg>` | setup.py, setup.cfg, pyproject.toml build hooks and package contents |\n| VS Code / Open VSX extension | `vscode <id or .vsix>` | activation events, dangerous APIs and bundled code, plus the extension's own identity |\n| Source trees | `scan` | code patterns across JavaScript, TypeScript, Python, shell, Go, Rust and more |\n| Cargo / Go | `scan` | build.rs, proc macros, go.mod replace directives, init() functions, CGo |\n| Docker | `scan` | Dockerfile, Dockerfile.*, Containerfile hardening (instructions only) |\n| Terraform | `scan` | provisioners, external module sources, hardcoded secrets |\n| GitHub Actions | `scan` | .github/workflows: unpinned actions, secrets exfiltration, injection, agentic workflows |\n| npm lockfiles | `scan` | integrity hashes, non-registry resolved URLs, version downgrades (package-lock.json, pnpm-lock.yaml, yarn.lock v1 and Berry, bun.lock) |\n| GitHub repositories | `repo` | trust signals, releases, README lures |\n| Solana | `monitor` | C2 wallet memo transactions |\n\n## How It Compares\n\nsupply-chain-guard is the malware / behavior / campaign-IOC layer: it statically scans what you actually install (node_modules, packages, Docker images, VS Code extensions, Actions workflows, IaC) for malicious behavior and known campaign indicators, entirely locally. It does NOT do CVE lookups: pair it with osv-scanner or npm audit for known vulnerabilities. Most tools below measure a different axis and are complementary, not competitors.\n\nThere is one axis where it goes somewhere the others do not go at all. Credential scanners such as gitleaks and trufflehog hunt secrets, and they are good at it; nothing in that category hunts what a repository gives away *about the network it came from*. That is what [Internal Disclosure](#internal-disclosure) covers: internal hostnames, private addresses, self-hosted forge URLs and developer paths, reported as reconnaissance risk rather than as a leaked credential.\n\n| Tool | Focus | Malware / behavior detection | Known-CVE lookup | Ecosystems | Open source | Account needed |\n|---|---|---|---|---|---|---|\n| **supply-chain-guard** | Malware campaigns, IOCs, behavior heuristics in installed artifacts; SBOM + SLSA provenance grading (in-toto/DSSE structural validation) | Yes: 350+ static heuristics plus multi-source GHSA/OpenSSF package verdicts and campaign-IOC matching, local at scan time (recent and curated indicators offline, the historical package catalog after a `feed refresh`) | No | 15 ecosystems of packages, extensions, plugins, providers, images and CI actions with shipped indicators, and tested matchers for more (see [Ecosystem Coverage](#ecosystem-coverage)), plus GitHub repos | Yes (Apache-2.0) | No |\n| [OSV-Scanner](https://github.com/google/osv-scanner) | Known vulnerabilities in dependency inventories (OSV.dev database lookup) | Known-malicious versions via OSV MAL- entries only; no behavior or IOC analysis | Yes (offline mode available) | 11+ ecosystems, 19+ lockfile formats, container images, SBOM input | Yes (Apache-2.0) | No |\n| [Socket](https://socket.dev) | Proactive behavioral analysis of entire registries (SaaS) | Yes: 70+ risk types registry-wide, before advisories exist; engine is closed source and cloud-side | Yes | npm, PyPI, Maven, Go, Cargo, RubyGems, NuGet, more; Actions workflows | CLI only (MIT); detection engine proprietary | Yes (except Firewall Free) |\n| [GuardDog](https://github.com/DataDog/guarddog) | Heuristic 0-10 risk scoring of individual packages (YARA + registry metadata) | Yes: heuristics only, no known-malware or campaign-IOC database; sandboxed scanning | No | npm, PyPI, Go, RubyGems, GitHub Actions, VS Code extensions | Yes (Apache-2.0) | No |\n| [OpenSSF Scorecard](https://github.com/ossf/scorecard) | Security-practice score of upstream repos (branch protection, pinning, review) | No: rates project hygiene, never analyzes published package contents | Only for the rated repo itself (OSV check) | GitHub repos, partial GitLab | Yes (Apache-2.0) | No (GitHub token for self-run CLI) |\n| npm audit | Advisory lookup for your npm dependency tree, built into npm | Known-malicious versions after an advisory is published; no behavior or IOC analysis; `audit signatures` verifies provenance | Yes (GitHub Advisory Database) | npm only | Yes (CLI; lookup is a registry-side service) | No |\n\nHonest caveats: Socket's registry-wide behavioral detection is deeper than anything a local scanner can do, at the cost of a closed engine and cloud analysis. Scorecard is the industry standard on its axis (upstream hygiene prediction) and supply-chain-guard does not replace it. OSV-Scanner and npm audit do flag known-malicious packages: the gap is advisory lag, not a missing capability.\n\n### Pairs well with\n\n- **CI one-two punch**: run `osv-scanner --lockfile=package-lock.json` for known CVEs and MAL- entries, then `supply-chain-guard scan .` for behavioral and campaign-IOC threats in the installed tree. Two axes, one job, both exit-code gated.\n- **Zero-install npm baseline**: `npm audit --audit-level=high` plus `npx supply-chain-guard scan .` covers advisory-known vulnerabilities and unreported malware without adding a single dependency.\n- **Pre-install vetting of a suspicious package**: `guarddog npm scan <pkg>` for an independent heuristic score, plus `supply-chain-guard npm <pkg>` for campaign-IOC and install-hook analysis, before it ever touches your machine.\n## EU Compliance (CRA / NIS2)\n\nsupply-chain-guard produces artefacts and findings that **support** compliance\nwork under two EU regulations that apply to software manufacturers. It does not\nmake an organisation compliant: compliance remains the responsibility of the\norganisation deploying the software, and the mapping below describes what the\ntool produces, not a legal assessment.\n\n### Cyber Resilience Act (CRA)\n\nThe CRA requires manufacturers of products with digital elements to identify and\ndocument the components they ship, to address vulnerabilities in those\ncomponents, and to be able to reason about the integrity of what they build on.\nsupply-chain-guard contributes to each of those activities:\n\n- **Component inventory:** generates a [CycloneDX 1.6](https://cyclonedx.org/)\n  SBOM from the real resolved dependency tree, as a machine-readable component\n  list you can attach to technical documentation. The inventory is built from\n  **npm only**, and specifically from `package-lock.json` (lockfile version 2 or\n  later) for the full transitive tree, falling back to the direct dependencies\n  declared in `package.json`. `pnpm-lock.yaml`, `yarn.lock` and `bun.lockb` are\n  **not** read, and neither is any non-npm manifest: a Python, Cargo, Go,\n  RubyGems, Composer or NuGet project produces an SBOM with no components from\n  that ecosystem. Every such file that is present is named in the document, in\n  `metadata.properties`, alongside an `inventory-coverage` value of\n  `full-transitive`, `direct-only` or `none`, so an inventory that was never\n  taken is never mistaken for a product that ships nothing. The scanner's threat\n  detection covers all the ecosystems listed at the top of this README; only the\n  SBOM inventory is npm-scoped.\n- **Dependency risk:** detects known-malicious packages and versions,\n  typosquatting, dependency confusion, and compromised publisher activity, at\n  scan time and at install time.\n- **Supply chain integrity:** grades SLSA provenance from levels 0 to 3 by\n  parsing and structurally validating in-toto/DSSE attestations, giving a\n  recorded integrity signal per project.\n\n```bash\n# Write a CycloneDX 1.6 SBOM alongside the scan report\nsupply-chain-guard scan ./project --sbom-output sbom.json\n```\n\n`--sbom-output <file>` and `--format sbom` produce the SAME document for the\nsame scan: the same components, the same dependency graph, the same\n`vulnerabilities` entries and the same incident annotations. Only the\n`serialNumber` and the timestamps differ, because each invocation is its own\nrun. The two exist so an SBOM can be written to a file while the scan report\nitself goes to stdout in another format.\n\n#### What the SBOM carries, and what it says it could not assess\n\nFrom `package-lock.json` (v2 or later) every component carries a stable\n`bom-ref`, a `purl`, the integrity hashes, the CycloneDX `scope`, and the\nlicence the lockfile declares, expressed as an SPDX `expression` when the string\nis an expression and as `license.id` when it is a plain SPDX identifier. An\nidentifier the generator cannot vouch for is kept as `license.name` rather than\nasserted as SPDX, because the CycloneDX schema constrains `license.id` to the\nSPDX enum. Relationships are emitted as a top level `dependencies` array rooted\nat the subject component and resolved the way npm resolves them, so a nested\nduplicate is linked to the dependent that actually installed it rather than to\nthe hoisted copy.\n\nWhat could not be assessed is stated instead of left blank. A component whose\nmanifest declares no licence carries a `supply-chain-guard:license` property\nsaying so, so an empty licence column is never read as \"no licence terms\". At\nthe document level, `metadata.properties` records which manifest the inventory\ncame from, how many components carry a declared licence, whether the dependency\ngraph was resolved, partial or not assessed, and how many declared edges resolve\nto no component in the document (uninstalled optional peer dependencies,\nnormally). A declared edge whose target is not in the document is counted there\nrather than emitted as a `dependsOn` pointing at a `bom-ref` that does not\nexist.\n\n```bash\n# What this SBOM says it could and could not assess\nsupply-chain-guard scan ./project --format sbom > sbom.json\nnode -e \"const d=require('./sbom.json');for (const p of d.metadata.properties ?? []) console.log(p.name, '=', p.value)\"\n```\n\nFindings removed by a `suppress:` entry in `.supply-chain-guard.yml` are emitted\nas CycloneDX VEX statements, with the reason the policy declared carried\nverbatim in `analysis.detail`. No `analysis.justification` is emitted: that\nfield is a fixed enum that a free-text reason cannot be mapped to. A suppression\nwith no recorded reason produces a statement that says exactly that.\n\nComponent hashes are hexadecimal digests, decoded from the base64 Subresource\nIntegrity value npm writes into the lockfile, because that is the encoding the\nCycloneDX `hash-content` pattern requires. An integrity part whose algorithm is\nnot one this generator maps, or whose payload does not decode to the digest\nlength its algorithm requires, is dropped and reported on the component rather\nthan emitted, and counted at the document level. purls are canonical: the npm\nscope is the purl namespace and the separator after it is a literal `/`.\n\nWhere the inventory came from `package.json` because no lockfile was present, a\ncomponent carries `version` and `purl` only when the manifest declares one exact\nversion. A range, a dist-tag such as `latest`, a git or URL specifier and a\n`workspace:` protocol are constraints, not versions: those components carry\nneither field, a `supply-chain-guard:version` property records why, and\n`supply-chain-guard:declared-specifier` keeps the declared string verbatim.\n\nSupplier and author are not emitted. `package-lock.json` does not carry either\nfield, and the SBOM generator reads only `package-lock.json` and `package.json`,\nso there is nothing to populate them from without a registry lookup.\n\nArticle and paragraph citations are deliberately omitted here. Map these outputs\nto specific provisions against the final published regulation text, with your own\nlegal review, rather than against this README.\n\n### NIS2 Directive\n\nNIS2 requires essential and important entities to take measures covering supply\nchain security. The relevant capabilities are:\n\n- **Supply chain risk:** typosquatting, dependency confusion, compromised\n  packages, and malicious GitHub Actions in CI/CD workflows.\n- **Incident evidence:** the correlation engine links individual findings into\n  named attack chains with confidence scores calibrated to indicator match\n  completeness. The incident record itself, with its name, confidence, indicator\n  counts (matched and total), list and narrative, is carried by three\n  formats: **JSON** (`incidents` on the report), **SARIF** (the incident list on\n  `runs[0].properties`, and the incidents each result belongs to in that\n  result's property bag) and **CycloneDX** (one `annotations` entry per\n  incident, whose `subjects` are the `vulnerabilities` entries it groups). The\n  text renderer prints it as a panel","readmeFilename":"README.md"}