
package-doctor
github.com/binuka200/package-doctor- Category
- Cybersecurity
- Rank
- No. 2257Tools index
- Pricing
- Open Source
- Type
- TOOL
- GitHub
- 8 stars
- Latest release
- v1.0.2
- Date
About
package-doctor is an MIT-licensed open source scanner that checks Python project dependencies against CISA's Known Exploited Vulnerabilities list and FIRST's EPSS exploit-probability scores, so developers can prioritize fixing packages that are actively being exploited rather than just those with the most CVEs. It also flags packages that have had no release or commit in over two years, and ships a Claude Code hook that stops an AI coding agent from installing packages that match these risk criteria. It can run standalone, in CI pipelines, or as that agent hook.
Tags
pythondependency-scanningcvesupply-chain-securitycisa-kevclaude-code
Tech Stack
Python
Media
Comments (0)
No comments yet
Editorially curated, with community endorsements as a secondary signal. Corrections welcome.