PMG GitHub Banner

Package Manager Guard (PMG)

[![Docs](https://img.shields.io/badge/Docs-docs.safedep.io-2b9246?style=flat-square)](https://docs.safedep.io/pmg/quickstart) [![Website](https://img.shields.io/badge/Website-safedep.io-3b82f6?style=flat-square)](https://safedep.io) [![Discord](https://img.shields.io/discord/1090352019379851304?style=flat-square)](https://discord.gg/kAGEj25dCn) [![Go Report Card](https://goreportcard.com/badge/github.com/safedep/pmg)](https://goreportcard.com/report/github.com/safedep/pmg) ![License](https://img.shields.io/github/license/safedep/pmg) ![Release](https://img.shields.io/github/v/release/safedep/pmg) [![OpenSSF Scorecard](https://api.securityscorecards.dev/projects/github.com/safedep/pmg/badge)](https://api.securityscorecards.dev/projects/github.com/safedep/pmg) [![CodeQL](https://github.com/safedep/pmg/actions/workflows/codeql.yml/badge.svg?branch=main)](https://github.com/safedep/pmg/actions/workflows/codeql.yml)

pmg in action
## Why PMG? Developers and AI coding agents install packages every day. Each `npm install` or `pip install` executes thousands of lines of code that nobody reviews. Malicious packages ship constantly in popular ecosystems: - [**litellm 1.82.8**](https://safedep.io/malicious-litellm-1-82-8-analysis/) - a popular AI proxy library compromised to exfiltrate credentials - [**telnyx 4.87.2**](https://safedep.io/malicious-telnyx-pypi-compromise/) - a legitimate telecom SDK hijacked on PyPI - [**pino-sdk-v2**](https://safedep.io/malicious-npm-package-pino-sdk-v2-env-exfiltration/) - a typosquat package disguised as the popular pino logger PMG intercepts every package install and checks it for malware **before** code executes. Install it once, and every `npm install`, `pip install`, and `poetry add` is protected automatically. > Featured in [tl;dr sec](https://tldrsec.com/p/tldr-sec-316) and used by engineering teams worldwide. ## How PMG Works - **Transparent Protection** - PMG wraps `npm`, `pip`, and other package managers to transparently apply protection. Developers and AI agents use their tools as usual with no workflow changes. - **Malicious Package Protection** - Every intercepted package is analyzed against [SafeDep's real-time threat intelligence](https://safedep.io) before installation. Malicious packages are blocked before code executes on the system. - **Sandboxed Installation** - Package installation runs inside OS-native sandboxes (macOS Seatbelt, Linux Bubblewrap), preventing install scripts from modifying the system even if a threat evades detection. - **Audit Logging** - Every package installation event is logged, providing a verifiable trail of what was installed, when, and from where. ## Quick Start Get protected in seconds. ### 1. Install **MacOS / Linux (Homebrew)** ```bash brew install safedep/tap/pmg ``` **NPM** ```bash npm install -g @safedep/pmg ``` > See [Installation](#installation) for additional methods. ### 2. Setup Configure your shell to use PMG automatically. ```bash pmg setup install # Restart your terminal to apply changes ``` > **Tip:** Re-run `pmg setup install` after upgrading PMG to pick up new configuration options. ### 3. Use Use your package managers as usual or let your AI coding agent use them. PMG works silently in the background. ```bash npm install express # or pip install requests ``` Verify PMG is working by installing a test package. This is a harmless package flagged as malicious in the SafeDep database, specifically meant for testing: ```bash npm i safedep-test-pkg@0.1.3 ```
Expected output ``` ✗ Malicious package blocked - safedep-test-pkg@0.1.3 Reference: https://app.safedep.io/community/malysis/01KF5JYDND9XR94WNEJ2G74KY2 ✗ PMG: 1 packages analyzed, 1 blocked ```
## Features | Feature | Description | | -------------------------------- | ---------------------------------------------------------------------------------------------------------------- | | **AI Agent Safety Net** | Protects against malicious packages installed by AI coding agents (Claude Code, Cursor, Copilot, Windsurf). | | **Malicious Package Protection** | Real-time protection against malicious packages using [SafeDep](https://docs.safedep.io/cloud/malware-analysis). | | **Sandboxing** | Enforces least privilege using OS native sandboxing to contain installation scripts. | | **Dependency Analysis** | Deep scans of direct and transitive dependencies before they hit your disk. | | **Event Logging** | Keeps a verifiable audit trail of all installed packages. | | **Zero Config** | Works out of the box with sensible security defaults. | | **Cross-Shell** | Seamlessly integrates with Zsh, Bash, Fish, and more. | ## Supported Package Managers PMG supports the tools you already use: | Ecosystem | Tools | Status | Command Example | | ----------- | -------- | ------ | ------------------- | | **Node.js** | `npm` | Yes | `npm install ` | | | `pnpm` | Yes | `pnpm add ` | | | `yarn` | Yes | `yarn add ` | | | `bun` | Yes | `bun add ` | | | `npx` | Yes | `npx ` | | | `pnpx` | Yes | `pnpx ` | | **Python** | `pip` | Yes | `pip install ` | | | `poetry` | Yes | `poetry add ` | | | `uv` | Yes | `uv add ` | ## Installation
Homebrew (MacOS/Linux) ```bash brew tap safedep/tap brew install safedep/tap/pmg ```
NPM (Cross-Platform) ```bash npm install -g @safedep/pmg ```
Go (Build from Source) ```bash # Ensure $(go env GOPATH)/bin is in your $PATH go install github.com/safedep/pmg@latest ```
Binary Download Download the latest binary for your platform from the [Releases Page](https://github.com/safedep/pmg/releases).
## Uninstallation Remove shell integration: ```bash pmg setup remove ``` To also remove the PMG configuration file: ```bash pmg setup remove --config-file ``` Then uninstall PMG itself: ```bash # Homebrew brew uninstall safedep/tap/pmg # NPM npm uninstall -g @safedep/pmg ``` ## Trust and Security Security is our first class requirement. PMG builds are reproducible and signed. * **Attestations**: GitHub and npm attestations are used to guarantee artifact integrity. * **Verification**: Users can cryptographically prove the binary matches the source code. * See [Trusting PMG](docs/trust.md) for verification steps. ## User Guide * [Trusted Packages Configuration](docs/trusted-packages.md) * [Proxy Mode Architecture](docs/proxy-mode.md) * [Sandboxing Details](docs/sandbox.md) ## Support If PMG saved you from a bad package, [star this repo](https://github.com/safedep/pmg) — it helps others find it. ## Contributing Contributions are welcome! Please see [CONTRIBUTING.md](CONTRIBUTING.md) for guidelines on how to build and test PMG locally. ## Telemetry PMG collects anonymous usage data to improve project stability and reliability. To disable: `export PMG_DISABLE_TELEMETRY=true`.