depshieldx is an open-source command-line tool for installing and scanning packages from PyPI, npm, Yarn, pnpm, and Cargo. It checks cryptographic provenance, looks up CVEs, analyzes Docker images with Trivy and behavioral tracing, and generates signed receipts.
depshieldx sits in PulseGate's Security & compliance platforms category. It focuses on reducing software supply-chain risk when installing packages and scanning container dependencies. It is built as an open-source project for software developers and DevSecOps teams. depshieldx is open source under the Apache-2.0 license. depshieldx is available on the command line, and it can be self-hosted.
Behind depshieldx is tee-wealth001, and it first shipped in 2026. The project is developed in the open on GitHub with 52 commits in the last 90 days. Key capabilities include package scanning, provenance checks, and CVE lookups.
Summary written by a language model from the project’s public pages.
What PulseGate has recorded for this listing
Closest matches by what these projects do