πŸ” Search
Sign in to post
Show HN: DepWarden – free, anonymous dependency vulnerability scannerhttps://depwarden.in/blog/npm-pypi-typosquatting-2026-report

No account, no source upload β€” paste a manifest/lockfile and get OSV+KEV+EPSS-prioritized findings in a session-isolated workspace. Also ran a typosquat study: checked every single-char typo of the 30 most popular npm/PyPI packages against the real registries and OSV's malicious-package DB β€” 32.7% of registered npm look-alikes are already confirmed malicious. Data/methodology: https://depwarden.in/blog/npm-pypi-typosquatting-2026-report Comments URL: https://news.ycombinator.com/item?id=49596333 Points: 1 # Comments: 0

β†—

0trust.social media

Loading your media...

Pick a GIF β€” Giphy

Loading GIFs...