Introducing vetpkg.dev - Open Source Component Security Dashboard
On this page
Introducing vetpkg.dev
vetpkg.dev is a free service that provides visibility into the security of open source components. It is built using the SafeDep Cloud API to provide an easy to use interface for developers to check the security of their open source dependencies before using them in their projects.
Why did we build vetpkg.dev?
As the developers of vet, we often felt the need for customizing security metadata visualization for open source components. We wanted to mash up public and private data sources to provide easy access to aggregated security data. We expect that this information will help developers and security engineers make better decisions about the open source components before using them in their projects.
Using vetpkg.dev, we want to provide a simple and easy-to-use interface for
having a single source of truth for open source component security information
including malicious code
analysis results.
How to use vetpkg.dev?
Using vetpkg.dev is simple. You can search for an open source component by
its ecosystem, name and version. For example, navigate to the following URL
You can also search for specific component by navigating to vetpkg.dev
How does vetpkg.dev work?
vetpkg.dev uses the SafeDep Cloud API to fetch security information about open
source components. This includes information about known vulnerabilities, licenses,
project metadata, malicious code analysis results and more. It uses SafeDep
Insights API to
fetch the required information.
Example
The source of screenshot below is available here

- sca
- nextgen-sca
- reachability
- ossrisk
- guide
Author
SafeDep Team
safedep.io
Share
The Latest from SafeDep blogs
Follow for the latest updates and insights on open source security & engineering
DirtyBlanket: Fake Express Packages on npm Spread a Linux Worm
Nine fake Express and React packages on npm run a Linux worm at install time. It installs a Tor backdoor and spreads through SSH, AUR packages, and npm tokens.
Mini Shai-Hulud Is Still Infecting GitHub Repositories
The May 2026 Mini Shai-Hulud worm is still infecting new GitHub repositories. Hijacked actions-cool/issues-helper tags planted Claude Code and VS Code hooks in six popular repositories between 20 and...
Detecting Compromised AI Coding Agents with Jev and Gryph
I checked every action of my own Claude Code agent against a profile of how I work and a set of org policies, using Jev. It caught 14 of 14 attacks for $0.15 per 1,000 events.
MemTensor npm and PyPI Packages Hit by a Go Worm
An attacker used a Go worm to steal CI publish tokens from MemTensor and ship malicious MemOS packages to npm and PyPI. See how it works, with code and indicators of compromise.
Ship Code.
Not Malware.
Start free with open source tools on your machine. Scale to a unified platform for your organization.