2025-04-23 22:38:39 +05:30
2025-04-23 22:38:39 +05:30
2025-04-23 22:38:39 +05:30
2025-04-21 21:13:23 +05:30
2025-04-23 22:38:39 +05:30
2025-04-23 22:38:39 +05:30
2025-03-20 07:59:48 +05:30
2025-04-09 23:27:46 +05:30
2025-04-21 21:13:23 +05:30
2025-04-23 02:21:44 +05:30

PMG (Package Manager Guard)

PMG is a security-focused wrapper for package managers that helps detect and prevent the installation of potentially malicious packages.

📑 Table of Contents

Supported Ecosystems

Currently, PMG supports the following package ecosystems:

Ecosystem Status Command
NPM Active pmg npm install <package>
PyPI 🚧 Planned Coming soon
Go 🚧 Planned Coming soon

Installation

  • Build from source

Ensure $(go env GOPATH)/bin is in your $PATH

go install github.com/safedep/pmg

Prerequisites

  • Go 1.24
  • SafeDep API credentials (SAFEDEP_API_KEY and SAFEDEP_TENANT_ID)

Environment Variables

  • SAFEDEP_API_KEY: Your SafeDep API key
  • SAFEDEP_TENANT_ID: Your SafeDep tenant ID
  • NPM_AUTH_TOKEN: (Optional) NPM authentication token for private packages

Usage

Scanning NPM packages

pmg npm install <package-name>

OR

pmg npm i <package-name>

OR

pmg npm add <package-name>

Contributing

Please feel free to submit a Pull Request.

Languages
Go 98.1%
JavaScript 1%
Shell 0.8%