Skip to content
@phylum-dev

Phylum

Phylum identifies risks and supply chain attacks in open-source package registries and provides developers with the tools to protect themselves.

Phylum ⦾ The Software Supply Chain Security Company

Phylum scans packages in open-source repositories, identifying threats, risks and supply chain attacks. We build tools to help developers and the organizations they work for block attacks, malware, and vulnerabilities from entering their software development lifecycle.

😄 Sign-up for a free Phylum account and start identifying and blocking risks in your software projects.

🔧 Open-Source Projects

The Phylum CLI provides direct access to the Phylum platform. Create and submit project lockfiles/manifest files (e.g., package-lock.json, requirements.txt, etc.)

Birdcage (Cross-platform Execution Sandbox)

A cross-platform sandbox used in the Phylum CLI to provide a locked down environment for package installation.

🌐 Find Us Online

🧟‍♂️ 2023: Softare Supply Chain Attack Reporting

We have successfully identified numerous supply chain attacks. So far in 2023 we've reported on:

Pinned

  1. cli cli Public

    Command line interface for the Phylum API

    Rust 99 10

  2. phylum-analyze-pr-action phylum-analyze-pr-action Public

    GitHub Action to analyze Pull Requests for open-source supply chain issues

    14 2

  3. birdcage birdcage Public

    Cross-platform embeddable sandboxing

    Rust 174 3

  4. install-phylum-latest-action install-phylum-latest-action Public

    GitHub Action to install phylum CLI tool

    1

  5. community-extensions community-extensions Public

    A collection of community extensions for the Phylum CLI

    TypeScript 1 1

  6. phylum-ci phylum-ci Public

    Python package for handling CI and other integrations

    Python 10 1

Repositories

Showing 10 of 25 repositories

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Top languages

Loading…

Most used topics

Loading…