Skip to main content
Open Source

PackageGuard

Get a grip on your open-source packages

$ packageguard . --report-risk
// licenses, vulnerabilities and project health โ€” one command, no account

Every score comes with its reasoning

--report-risk writes a self-contained HTML report and a matching SARIF file. The HTML has no scripts and no external assets, so you can publish it straight from a build. Every point a package loses is listed, with a link to the evidence behind it.

A PackageGuard risk report: package counts by risk zone, a status check summary, a package summary table, and a per-package breakdown into legal, security and operational scores with the reasoning behind each one
The top of a real report, with the per-package evidence lists left out to keep the picture short. Click it to see it full size.