Pkg-doctor is a CLI tool that scans local projects for known-vulnerable or malicious dependencies using OSV and SBOM data. It also provides guided help for rotating exposed API keys and secrets. It is aimed at developers who want to secure their Python or other project dependencies against supply-chain attacks.
In the Developer Tools space, pkg-doctor takes a focused approach. It focuses on detecting and fixing vulnerable, malicious, or exposed-secret dependencies in local software projects. It is built as an open-source project for developers. pkg-doctor is open source under the MIT license. pkg-doctor is available on the command line.
pkg-doctor first shipped in 2026. Key capabilities include vulnerability scanning, dependency checking, and secret rotation.
Summary written by a language model from the project’s public pages.
What PulseGate has recorded for this listing
Same category — not a similarity match