Stop babysitting your dependencies.

Risk Guard scans your dependency tree on every push and reports findings inline on your PR. Read-only by default—nothing blocks until you say so.

7 hrs avg time to fix one vulnerability
193 days mean time to adopt an upstream fix
36 checks run on every push
Read-only GitHub App · No config needed to start

Dependabot finds CVEs. Snyk finds CVEs.
Who finds everything else?

Your existing tools handle known vulnerabilities. But most supply chain incidents aren't CVEs when they ship. The xz-utils backdoor was social engineering over two years. colors/faker was a solo maintainer who broke 23 M weekly downloads on purpose. event-stream was a trust transfer attack.

Risk Guard adds the signals your stack is missing—maintainer health, package provenance, license compliance, supply chain integrity. It doesn't replace Dependabot or Snyk. It covers what they don't.

Five-minute setup. Zero config to start.

Install and go.

1

Install

Add the GitHub App to your org. Select repos.

github.com/apps/risk-guard

Read-only access. No webhooks, no build changes, no CI config.

2

Push

Open a PR. Findings appear as GitHub Check annotations inline on the diff.

Risk Guard 36 checks complete
0 blocking · 3 warnings · 33 passed
⚠
SOURCE_SINGLE_CONTRIBUTOR — warning
npm/left-pad · single contributor in past year
package.json:22 · my-app → build-tools → left-pad
⚠
PACKAGE_STALE_RELEASE — warning
npm/moment · no release in 3+ years
package.json:8 · my-app → moment

When you're ready

When you want more control, drop a config file in your repo.

.risk-guard.yml
version: 2
workflow:
  mode: active
severity:
  category/critical:
    severity: blocking

Critical findings block the PR. Everything else stays a warning. Override per-repo, per-check, or per-environment.

What your PR reviews start catching.

Active malware

Malicious code in the published package.

event-stream v3.3.6 — crypto wallet drainer injected via maintainer takeover.

Maintainer health

Bus factor, abandonment, single-author risk.

core-js — 9B downloads, one maintainer who threatened to quit.

Supply chain integrity

Typosquatting, source/registry mismatch, install scripts.

ua-parser-js — npm account hijacked, cryptominer injected into 7M weekly downloads.

License compliance

Copyleft propagation, commercial restrictions, missing declarations.

A transitive AGPL dependency in your SaaS triggers source disclosure obligations.

Provenance

Registry existence, name impersonation, hash verification.

colors v1.4.1 — published with infinite loop by the author. No CVE existed.

Vulnerability depth

Multi-source CVE aggregation, remediation velocity, unfixed vulns.

74,909 npm packages never adopted available vulnerability fixes.

Fits where you already work.

PR annotations, not a dashboard

Findings show up inline on the diff. No new tab. No weekly reports to ignore.

Policy in your repo, not a UI

.risk-guard.yml lives next to your code. Version-controlled, reviewable, diffable.

Complements your existing tools

Runs alongside Dependabot, Snyk, Renovate. Adds the signals they don't cover.

Try it on one repo. Five minutes.

Read-only GitHub App · Observe mode by default · Uninstall anytime

Install GitHub App
github.com/apps/risk-guard

OSS Risk Guard — Supply Chain Risk Intelligence