Detect malicious package releases before they enter your build.

Stop malicious package releases before they reach your build.

ReleaseWarden scans npm and PyPI updates, compares what changed, and gives CI a clear block or warn decision with evidence and safe-version guidance.

Detection model
release diff
Ecosystems
npm + PyPI
Free tier
20 scans/mo
Paid wedge
CI blocking

What it catches first

Current MVP is static and advisory-backed. Sandbox verdicts stay gated until containment is approved.

New install scripts
tracked
Malware-like advisories
context
Suspicious artifacts
flagged
Safe or patched version
recommended
Package execution verdicts
gated