Introducing vetpkg.dev - Open Source Component Security Dashboard
Table of Contents
Introducing vetpkg.dev
vetpkg.dev is a free service that provides visibility into the security of open source components. It is built using the SafeDep Cloud API to provide an easy to use interface for developers to check the security of their open source dependencies before using them in their projects.
Why did we build vetpkg.dev?
As the developers of vet, we often felt the need for customizing security metadata visualization for open source components. We wanted to mash up public and private data sources to provide easy access to aggregated security data. We expect that this information will help developers and security engineers make better decisions about the open source components before using them in their projects.
Using vetpkg.dev, we want to provide a simple and easy-to-use interface for having a single source of truth for open source component security information including malicious code analysis results.
How to use vetpkg.dev?
Using vetpkg.dev is simple. You can search for an open source component by its ecosystem, name and version. For example, navigate to the following URL
You can also search for specific component by navigating to vetpkg.dev
How does vetpkg.dev work?
vetpkg.dev uses the SafeDep Cloud API to fetch security information about open source components. This includes information about known vulnerabilities, licenses, project metadata, malicious code analysis results and more. It uses SafeDep Insights API to fetch the required information.
Example
The source of screenshot below is available here

- sca
- nextgen-sca
- reachability
- ossrisk
- guide
Author
SafeDep Team
safedep.io
Share
The Latest from SafeDep blogs
Follow for the latest updates and insights on open source security & engineering

Agent Skills Threat Model
Discover critical security threats in Agent Skills - Anthropic's open format for AI agent capabilities. Learn about supply chain attacks, deferred code execution, prompt injection, and multiple...

DarkGPT: Malicious Visual Studio Code Extension Targeting Developers
Malicious extensions are lurking in the Visual Studio Code marketplace. In this case, we discover and analyze DarkGPT, a Visual Studio Code extension that exploits DLL hijacking to load malicious...

The State of MCP Registries
Explore the architecture of the Model Context Protocol (MCP) and the state of its official registry. Learn how to consume server packages programmatically and discover the underlying challenges of...

Unpacking CVE-2025-55182: React Server Components RCE Exploit Deep Dive and SBOM-Driven Identification
A critical pre-authenticated remote code execution vulnerability (CVE-2025-55182) was disclosed in React Server Components, affecting Next.js applications using the App Router. Learn about the...

Ship Code
Not Malware
Install the SafeDep GitHub App to keep malicious packages out of your repos.
