Stop babysitting your dependencies.
Risk Guard scans your dependency tree on every push and reports findings inline on your PR. Read-only by default—nothing blocks until you say so.
Dependabot finds CVEs. Snyk finds CVEs.
Who finds everything else?
Your existing tools handle known vulnerabilities. But most supply chain incidents aren't CVEs when they ship. The xz-utils backdoor was social engineering over two years. colors/faker was a solo maintainer who broke 23 M weekly downloads on purpose. event-stream was a trust transfer attack.
Risk Guard adds the signals your stack is missing—maintainer health, package provenance, license compliance, supply chain integrity. It doesn't replace Dependabot or Snyk. It covers what they don't.
Five-minute setup. Zero config to start.
Install and go.
Install
Add the GitHub App to your org. Select repos.
github.com/apps/risk-guardRead-only access. No webhooks, no build changes, no CI config.
Push
Open a PR. Findings appear as GitHub Check annotations inline on the diff.
When you're ready
When you want more control, drop a config file in your repo.
version: 2
workflow:
mode: active
severity:
category/critical:
severity: blocking Critical findings block the PR. Everything else stays a warning. Override per-repo, per-check, or per-environment.
What your PR reviews start catching.
Active malware
Malicious code in the published package.
event-stream v3.3.6 — crypto wallet drainer injected via maintainer takeover.
Maintainer health
Bus factor, abandonment, single-author risk.
core-js — 9B downloads, one maintainer who threatened to quit.
Supply chain integrity
Typosquatting, source/registry mismatch, install scripts.
ua-parser-js — npm account hijacked, cryptominer injected into 7M weekly downloads.
License compliance
Copyleft propagation, commercial restrictions, missing declarations.
A transitive AGPL dependency in your SaaS triggers source disclosure obligations.
Provenance
Registry existence, name impersonation, hash verification.
colors v1.4.1 — published with infinite loop by the author. No CVE existed.
Vulnerability depth
Multi-source CVE aggregation, remediation velocity, unfixed vulns.
74,909 npm packages never adopted available vulnerability fixes.
Fits where you already work.
PR annotations, not a dashboard
Findings show up inline on the diff. No new tab. No weekly reports to ignore.
Policy in your repo, not a UI
.risk-guard.yml lives next to your code. Version-controlled, reviewable, diffable.
Complements your existing tools
Runs alongside Dependabot, Snyk, Renovate. Adds the signals they don't cover.
Try it on one repo. Five minutes.
Read-only GitHub App · Observe mode by default · Uninstall anytime
Install GitHub AppOSS Risk Guard — Supply Chain Risk Intelligence