DhanushNehru / lockcheck
PublicA zero-dependency Node.js CLI tool that scans package-lock.json for suspicious patterns that indicate supply chain attacks.
lockcheck scans project lock files for suspicious dependency changes like new packages, typosquats, and version anomalies to detect potential supply chain attacks.
How It Works
You learn about a handy safety tool that watches for sneaky changes in your app's building blocks to keep things secure.
Go to the folder holding your project on your computer.
Start the quick scan, and it captures your current setup as a trusted baseline.
Bring in fresh tools or update your app's pieces as you build.
Run the check once more to spot any new or odd additions that might be risky.
See clear warnings about suspicious look-alikes, brand-new items, or weird shifts.
With issues flagged and fixed, your app stays protected from hidden threats.
Star Growth
Repurpose is a Pro feature
Generate ready-to-use prompts for X threads, LinkedIn posts, blog posts, YouTube scripts, and more -- with full repo context baked in.
Unlock RepurposeSimilar repos coming soon.