orewatch is an open-source CLI tool for detecting malicious packages and monitoring dependencies across various programming ecosystems. It supports SBOM scanning and continuous background monitoring, helping developers and security teams maintain secure software supply chains.
orewatch sits in PulseGate's Malware analysis & digital forensics category. It helps developers detect and monitor malicious packages and dependencies across multiple ecosystems. It is built as an open-source project for software developers and security teams. orewatch is open source under the MIT license. orewatch is available on the web and the command line.
rapticore builds and maintains orewatch, and it first shipped in 2025. The project is developed in the open on GitHub with 30 commits in the last 90 days. Key capabilities include malicious package detection, dependency monitoring, and multi-ecosystem support.
Summary written by a language model from the project’s public pages.
What PulseGate has recorded for this listing
Same category — not a similarity match