SafeDep is an open-source tool designed to protect developers from Supply Chain Attacks. It analyzes packages and dependencies for malicious behavior, data exfiltration, and hidden vulnerabilities before you even install them.
"Don't just scan for known vulnerabilities. Detect suspicious behavior."
The package ecosystem (PyPI, NPM, Cargo) is under constant attack from Typosquatting, Dependency Injection, and Trojan Horses. SafeDep goes beyond standard vulnerability databases (CVEs) by analyzing both the static and dynamic behavior of the code.
- 🔍 Pre-install Sandbox: Runs installation scripts in an isolated environment to monitor what they attempt to access.
- 📡 Network Monitor: Alerts you if a "text processing" package tries to make requests to unknown IP addresses.
- 🔑 Secret Leak Detection: Identifies if a package attempts to read your environment variables (
.env) or API keys. - 🏷️ Typosquatting Protection: Checks if a package name is dangerously similar to a popular one.
To use SafeDep locally, clone the repository and install it in editable mode:
# create a virtual environment
python3 -m venv venv
source venv/bin/activate
# Install dependencies
pip install -r requirements.txt
# Install SafeDep in editable mode (so code changes are reflected immediately)
pip install -e .For behavioral analysis, Docker or Podman must be installed and running.
# Check if docker is available
docker --versionSafeDep provides several commands:
Analyzes a package (remote) for typosquatting and reputation risks.
Python (default):
safedep check <package_name>Python Typosquatting Example:
# Detects similarity to 'requests'
safedep check requesstNPM:
safedep check <package_name> --ecosystem npmCargo (Rust):
safedep check <package_name> --ecosystem cargoScans local files (Python, JS, TS, NPM, Cargo) for dangerous code patterns or suspicious dependencies (in requirements.txt, package.json, Cargo.toml).
SafeDep automatically excludes common dependency and internal directories like venv, node_modules, and .git to focus on your project's source code.
safedep scan <path_to_directory>Runs a package installation in a Docker container and monitors for suspicious system calls.
Python:
safedep check <package_name> --sandboxNPM:
safedep check <package_name> --ecosystem npm --sandboxCargo:
safedep check <package_name> --ecosystem cargo --sandbox- ✅ Implementation of name similarity analysis (Anti-Typosquatting).
- ✅ Reputation verification (package creation date, author history).
- ✅ Static code scanner for dangerous functions.
- ✅ Sandboxing: Integration with Docker/Podman to run setup.py and monitor system calls (syscalls).
- ✅ Multi-language Support: Support for NPM (Node.js) and Cargo (Rust) in addition to Python.
- ✅ CI/CD Integration: GitHub Actions to block PRs with suspicious dependencies.
- SafeDep Hub: A community-driven database of "audited and clean" packages.
- Security Badges: A system for repositories to display security trust seals.
- [/] Sponsorship Program: Launching the Sponsors program to maintain the heavy analysis infrastructure.
The SafeDep Hub is a crowdsourced database of packages that have been manually audited by the community and verified as safe.
- When you run
safedep check <package>, the tool queries the Hub. - If the package is found, you'll see the SafeDep Shield and a Markdown snippet to add a trust badge to your repo.
- Contributions are made via Pull Requests to the
hub/audited_packages.jsonfile.
If your package is audited, display your trust seal:
[](https://github.com/marcioreck/safedep)
SafeDep is a zerocost marketing open-source initiative. We rely on community audits to grow "The Shield".
- Audit a Package: Submit a PR to the Hub.
- Give a ⭐: Help us reach more developers.
- Report Bugs: Help us improve the scanner.
- Become a Sponsor: Support the infrastructure for deep behavioral analysis.
Developed for those who prioritize security.