SafeDep vet

Open source tool for supply chain security analysis in CI/CD pipelines — scans for malicious packages.

Visit Website
docs.safedep.io
Verified Free tier
Quick facts
What is it Open source tool for supply chain security analysis in CI/CD pipelines — scans for malicious packages.
Pricing Freemium — from $20/mo
Free tier Yes
Platform Web Application
Best for scanning project dependencies for malicious packages, integrating security checks into CI/CD pipelines
Domain registered 2022

Data updated Aug. 1, 2026

What does SafeDep vet do?

SafeDep vet is an open source tool designed to analyze and secure your software supply chain directly within your CI/CD pipelines. It scans the open source packages your project depends on, checking for malicious code and other security risks. The tool works by integrating with platforms like GitHub and GitLab, allowing automated security checks every time code is built or deployed.

What makes SafeDep vet stand out is its foundation on a large-scale malicious package scanning infrastructure. It uses a combination of static and dynamic analysis to detect threats, and suspicious findings are verified by security experts. The tool is part of a broader suite of free, open source utilities from SafeDep, including tools for protecting developers from malicious packages, generating enriched SBOMs, and creating audit trails for AI coding agents. You can use vet completely independently, without needing a commercial relationship with the SafeDep Cloud platform.

This tool is built for security engineers, development teams, and DevOps professionals who need to manage open source risks without slowing down their workflow. It's particularly useful for organizations that rely heavily on open source libraries and want to automate their security posture. Real-world use cases include automatically blocking risky dependencies from entering a codebase, generating compliance-ready SBOMs, and securing projects that utilize AI coding assistants.

#ci-cd#devsecops#malware-scanning#open source#sbom#security analysis#supply chain security

Key features

What makes it stand out
01
Scans open source packages for malicious code using static and dynamic analysis
02
Integrates with GitHub, GitLab, and other CI/CD platforms
03
Provides a free, open-source tool for security analysis
04
Generates enriched SBOMs with AI and crypto metadata
05
Creates an audit trail for AI coding agents

Who is SafeDep vet for?

Who benefits most from this tool
scanning project dependencies for malicious packages
integrating security checks into CI/CD pipelines
generating software bills of materials (SBOMs) for audits

Pricing

Free tier available — start without a credit card

Free

Free
  • 3 team members
  • 1,000 scans per month
  • Open Source SCA
  • CI/CD Integration
  • GitHub App
  • Known Malicious Package Detection
  • Unlimited Public Repos
  • 3 Team Members
  • 1000 Scans per month
  • Fair Usage Policy

Professional

$20.0/month

Everything in Free, plus:

  • Real-time Malicious Package Feed
  • On-demand Malicious Package Scanning
  • Developer CLI, IDE Protection
  • Central Policy Management
  • Hosted MCP Server
  • Supply Chain Inventory and Query (SQL)
  • Team Collaboration
  • Unlimited Repos and Scans

Enterprise

Custom

Everything in Professional, plus:

  • Human in the Loop Malware Triage
  • Software Supply Chain Transparency and Compliance Auditing
  • Support SLA
  • Single Sign-On (SSO)
  • SOC2 and ISO 27001 reports
  • Custom Integrations
  • Custom API and Resource Limits

Trust & presence

Domain Domain registered 2022

Gallery

Click any image to enlarge

Alternatives in Developer Tools

CybeDefend Verified Developer Tools

AI-powered application security platform that scans code, dependencies, and infrastructure for vulnerabilities and provides automated fixes.

ZeroPath Verified Developer Tools

AI-powered code security scanner that finds, verifies, and auto-fixes vulnerabilities like business logic flaws and broken auth.

Cycode Verified Developer Tools

AI-powered application security platform that protects code from development to runtime with automated risk detection and remediation

Trace-AI Verified Developer Tools

AI-powered software supply chain security — generates real-time SBOMs, scans for exploitable vulnerabilities, and tracks license compliance.

CICube Verified Developer Tools

AI DevOps agent for GitHub Actions — monitors workflows, detects failures, suggests fixes, and optimizes CI/CD costs

binarly.io Verified Developer Tools

AI-powered platform for firmware and software supply chain security — detects vulnerabilities, malicious code, and dependencies in binaries.

Top 100k site
Securevector Verified Developer Tools

Open-source AI agent security — monitors, audits, and blocks threats on-device with optional cloud governance

n8n
GitLab Verified Developer Tools

AI-powered DevSecOps platform that manages the entire software lifecycle from planning to deployment in one place

n8n · claude

Similar tools

ShellDef Verified Pentesting

AI-powered shell script scanner — paste or upload scripts to detect security risks and get fixes instantly.

VibeSec Verified Pentesting

AI-powered code security scanner — connect your GitHub repo, find vulnerabilities, and get actionable fix reports in seconds.

Share X LinkedIn Telegram
SafeDep vet Visit