Crates.io | hipcheck |
lib.rs | hipcheck |
version | 3.7.0 |
source | src |
created_at | 2024-05-09 22:52:56.850402 |
updated_at | 2024-10-10 16:56:11.270779 |
description | Automatically assess and score software packages for supply chain risk. |
homepage | https://mitre.github.io/hipcheck |
repository | https://github.com/mitre/hipcheck |
max_upload_size | |
id | 1235544 |
size | 811,481 |
Go from hundreds of dependencies you can't review, to just a few you can!
Managing the security risk of third-party software at scale is difficult. Normal projects can easily have hundreds of dependencies; far too many to review by hand.
Hipcheck is designed to help you filter that list of dependencies down to just a few that appear concerning, and to give you the information you need to make a security decision quickly.
Hipcheck is a command line interface (CLI) tool for analyzing open source software packages and source repositories to understand their software supply chain risk. It analyzes a project's software development practices and detects active supply chain attacks to give you both a long-term and immediate picture of the risk from using a package.
For more information, see "Why Hipcheck?"
Hipcheck can analyze Git source repositories and open source packages from popular package hosts.
# Analyze Express, a popular JavaScript package for web servers, with the
# URL of its Git repository.
hc check https://github.com/expressjs/express
# Analyze urllib3 version 2.2.2, a popular URL-handling package hosted on PyPI.
hc check -t pypi urllib3@2.2.2
# Analyze the package described by an SPDX Software Bill of Materials.
hc check example-sbom.spdx.json
For more information, check out the Quickstart Guide.
See the Installation Instructions.
Hipcheck's product values are to be:
Read more about Hipcheck's product and project values in RFD #2.
Hipcheck's software is licensed under the Apache 2.0 license, which can be
found in the LICENSE
file in this repository.
[!NOTE] Approved for Public Release; Distribution Unlimited. Public Release Case Number 22-2145.
Portions of this software were produced for the U.S. Government under Contract No. FA8702-19-C-0001, W56KGU-18-D-0004, and 70RSAT20D00000001 and is subject to the Rights in Noncommercial Computer Software and Noncommercial Computer Software Documentation Clause DFARS 252.227-7014 (FEB 2014).