Vet: Open-source software supply chain security tool - Help Net Security
Vet helps developers and security teams detect vulnerabilities and malicious packages across ecosystems like npm, PyPI, Maven, Docker and more.
It features real-time threat detection and customizable policies via CEL, and integrates with CI/CD tools.