A Git-native dependency admission controller. Evaluates trust signals on every dependency change and blocks commits or builds when packages fail your team's policy. Pre-commit hook + CI gate with built-in approval workflow.
trustlock evaluates trust signals like package age, provenance attestations, version pinning, install scripts, and sources on dependency changes in supported lockfiles, running as a Git pre-commit hook in advisory mode and a CI check in enforce mode.
How It Works
You hear about trustlock, a friendly guard that checks new ingredients in your project to spot potential risks before they sneak in.
You easily bring trustlock into your project so it can watch over your dependencies.
Trustlock scans your current setup and saves a trusted snapshot of all your ingredients as a safety baseline.
You set it up to automatically check changes right before you commit your work.
Everything passes smoothly, and your baseline updates automatically.
Trustlock spots something new or risky and asks for your review.
For flagged items, you add a temporary okay with a reason, keeping an audit trail.
Your commits go through safely, with only trusted ingredients, and your safety baseline stays up to date.
Star Growth
Repurpose is a Pro feature
Generate ready-to-use prompts for X threads, LinkedIn posts, blog posts, YouTube scripts, and more -- with full repo context baked in.
Unlock RepurposeSimilar repos coming soon.