Show HN: An OSS Python dependency scanner for exploited, unmaintained packages
I built an open source python dependency scanner that will scan and flag packages with known exploit CVEs(CISA's Known Exploited list and FIRST EPSS) and unmaintained packages that have not had a release or commit in 2 years. Theres also claude hook that will make your AI agent not install these typ
Flagged by the ranking heuristics as a real, artifact-backed build.