SafeDep is a real-time open source software supply chain security platform. It focuses on detecting malicious packages and on governing what enters an organization’s stack across developer workflows and AI agents.
Its listed functions include discovering and monitoring SCA and SBOM data, scanning dependencies, generating SBOMs, and enforcing policy. SafeDep also provides AI Agent Discovery, AI Agent Monitoring, an Agent API for custom agents, and Threat Intelligence with real-time malicious package verdicts. The product page says it can block malicious packages at install-time, in CI/CD pipelines, inside AI coding agents, and across pull requests and builds. It also describes governance features such as centralized policies, a dashboard, and compliance reporting.
SafeDep says it builds a real-time inventory of external components flowing into an organization’s stack, including packages, MCP servers, plugins, extensions, and repositories, across developer and AI agents. Its threat intelligence engine analyzes components for typosquats, obfuscated code, data exfiltration, and known malicious patterns, and returns block, allow, or investigate decisions before a component reaches the codebase. The page also mentions endpoint protection for package events and AI inventory in the cloud, plus a central dashboard for threats, repository status, and policy compliance.
The page presents the product as working across developer machines, pull requests, CI/CD, and AI coding agents, and it names GitHub App installation with mention of GitLab or Bitbucket as a contact option. Pricing is listed on the site, and a Start for Free option appears in the page text. The page also includes links to documentation, SDK, API, a Threat Intelligence Hub, and login.
SafeDep sits in PulseGate's Security & compliance platforms category. It focuses on protecting software supply chains from malicious packages and open source risks. It is built as a B2B product for devops teams. It ships for the web, the command line, and API.
Behind SafeDep is SafeDep, and it first shipped in 2025. Development happens publicly on GitHub with 450 stars and 95 commits in the last 90 days. Key capabilities include SCA scanning, SBOM generation, and AI agent monitoring. It exposes integrations via an MCP server and a public API.
Summary written by a language model from the project’s public pages.
What PulseGate has recorded for this listing
Closest matches by what these projects do