mitkox / supply-chain-monitor-localai
PublicFork of https://github.com/elastic/supply-chain-monitor with local AI backend (vLLM/llama.cpp)
This tool automatically watches for new releases of the most downloaded Python and JavaScript packages, compares code changes using a local AI analyzer to identify potential malicious alterations, and sends notifications to a team chat if threats are detected.
How It Works
You learn about a helpful tool that keeps an eye on the most popular software packages to catch any sneaky dangerous updates.
You set up a local thinking machine that can carefully examine changes in package updates to spot anything harmful.
You connect it to your group's chat space so warnings about bad updates arrive instantly where everyone can see.
You start the watcher with a simple go command, and it begins scanning the busiest packages automatically.
The tool checks for fresh updates every few minutes in the background, without interrupting your day.
Whenever a risky change appears, you receive a clear warning with details, protecting your projects effortlessly.
Star Growth
Repurpose is a Pro feature
Generate ready-to-use prompts for X threads, LinkedIn posts, blog posts, YouTube scripts, and more -- with full repo context baked in.
Unlock RepurposeSimilar repos coming soon.