OPEN-SOURCE PROJECT
pkg-gate
Pre-install security gate for npm lifecycle scripts using TypeSafe System One. Evaluates preinstall, install, and postinstall hooks across intent, threat severity, secret access, and remote execution to intercept supply-chain attacks before execution.
- Stars
- 0
- Forks
- 0
- License
- MIT
- Last commit
- 2026-09-21
What Jev does here
pkg-gate uses `@typesafe-ai/sdk` to evaluate lifecycle scripts in parallel across intent (Choice), threat severity (Score), secret exfiltration (Noul), and remote execution (Noul).
Adds structured choices or scores to the workflow; performance and cost benefits have not been independently verified.
Author and repository text is preserved where clear; missing languages are enriched automatically. Checks establish source-level Jev integration, not runtime, safety, or performance validation.