Submit repository
Discover trends that matter
Trending repositories
Daily
Weekly
Monthly
Yearly
Live mentions
Topics
GitHub trending
Repositories
Developers
Insights
Stats
safedep/pmg — GitHub trending stats & insights | Trendshift
Featured
Bindu
Openhuman
Embed Badge
Visit GitHub
safedep/pmg
PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.
Go
380
28
15 contributors
Apache License 2.0
website
Social mentions
Recent discussions about this repository across the web
PMG path shims changed in v0.17.1. We were resolving symlinks in shims. This breaks how Homebrew manages binaries and it's own shims. If you face issues, run "pmg setup install" or update to fixed…
@abh1sek · x.com
Looking to collaborate with researchers in figuring out what are some effective controls to build in PMG that offers practical protection against the on-going supply chain attacks.
@abh1sek · x.com
If you are using PMG, you are always on safer side
@safedepio · x.com
PMG v0.17.0 is out. There are important fixes: 1. Fix dependency cooldown handling in npm/PyPI 2. Sandbox DevEx improvements Introduce per-project sandbox overlays (allowances) to customise the…
@abh1sek · x.com
> will takes 3 minutes to setup. > works everywhere without learning anything new. > free and open source quickstart:
@safedepio · x.com
> will takes 3 minutes to setup. > works everywhere without learning anything new. > free and open source quickstart:
@safedepio · x.com
But how do we establish this trust? We took a defence in depth approach. Not just depending on SafeDep's threat intelligence but built a policy and sandbox layer. Policy layer enforces dependency…
@abh1sek · x.com
pmg protects developers and AI agents from malicious open source packages. - Proxy + sandbox to intercept installs before they run - Backed by SafeDep's threat intelligence feed - Stop the next…
@so_sthbryan · x.com
5,700 malicious commits. 6 hours and all looked like routine CI noise. This is why blocking packages at install time matter because signed commits help at the commit layer
@safedepio · x.com
Gentle reminder. Dependency Cool-down would be an effective control against this week’s attack. If you are unable to update your package manager, try PMG. It enforces DC by default. Plus opt-in…
@abh1sek · x.com
Load more
Repository activities
repository's daily and monthly activities across stars, forks, merged PRs, issues, and closed issues
GitHub trending history
Shows when the repository has appeared on GitHub Trending across any language
go ranking