Lateos/NPM-scan – open-source NPM supply chain scanner, v0.18.3
NPM supply chain scanner competing against Socket, Snyk, and npm audit.

Lifecycle intelligence beyond CVEs, but SCA competitors already bundle EOL tracking.
Security teams, DevOps engineers, compliance officers managing open-source risk
Snyk · Dependabot · OWASP Dependency-Check
The reason we built it: most teams only find out they're running EOL software during a CVE incident or a compliance audit. We kept hearing this problem from customers and couldn't find a tool that clearly answered: which of my dependencies will never get another patch, including the ones your packages depend on?
SCA tools cover known CVEs. They don't cover EOL status or what's coming. That's the gap this is built for.
One thing worth saying directly: HeroDevs is a for-profit company. But part of why we built this is that we think someone needs to be a responsible steward for open source software when maintainers move on. We see this as part of that commitment, not just a product.
Run it with npx @herodevs/cli scan or upload an SBOM on the site (https://eoldataset.com/). Free to use. Curious what you find, especially in ecosystems we haven't covered well yet.
NPM supply chain scanner competing against Socket, Snyk, and npm audit.
Catches malicious AI skill scripts when Semgrep and Snyk miss the format.
Behavioral malware scanning before install, unlike pip-audit.
Single command upgrades Node and migrates global packages across eight version managers.
Local proxy blocking malicious installs before execution beats post-install scanning tools.
Fills the EDR blind spot for AI tooling — timely and actually useful today.