sherlockscan is an open-source command-line tool that statically scans Python packages for supply-chain security risks. It is intended for developers and security teams reviewing dependencies before deployment.
sherlockscan sits in PulseGate's Security & compliance platforms category. It focuses on identifying supply-chain risks in Python packages before they enter a software project. sherlockscan is an open-source project aimed at python developers and security teams. sherlockscan is open source under the MIT license. sherlockscan is available on the command line, and it can be self-hosted.
itsual builds and maintains sherlockscan, and it first shipped in 2025. The project is developed in the open on GitHub with 21 commits in the last 90 days. Key capabilities include package scanning, static analysis, and supply-chain checks.
Summary written by a language model from the project’s public pages.
What PulseGate has recorded for this listing
Closest matches by what these projects do