Vibeleaderboard
Index / tool
Visit github.com
Category
Cybersecurity
Rank
No. 2257Tools index
Pricing
Open Source
Type
TOOL
GitHub
8 stars
Latest release
v1.0.2
Date

About

package-doctor is an MIT-licensed open source scanner that checks Python project dependencies against CISA's Known Exploited Vulnerabilities list and FIRST's EPSS exploit-probability scores, so developers can prioritize fixing packages that are actively being exploited rather than just those with the most CVEs. It also flags packages that have had no release or commit in over two years, and ships a Claude Code hook that stops an AI coding agent from installing packages that match these risk criteria. It can run standalone, in CI pipelines, or as that agent hook.

Tags

pythondependency-scanningcvesupply-chain-securitycisa-kevclaude-code

Tech Stack

Python

Media

package-doctor

Comments (0)

No comments yet

Editorially curated, with community endorsements as a secondary signal. Corrections welcome.