JevMade Sign in
← Back to experiments

Apps & data pipelines

pkg-gate

Bookmark: pkg-gate Keep this in your collection.
Leave a noteWhat would you try with this? : pkg-gate

Only you can see your notes.

Source screenshot of pkg-gate
SOURCE SCREENSHOTFull screenshot ↗

What it does

A pre-install security gate that uses Jev to inspect npm lifecycle scripts before they run.

How you can use it

A developer can adapt this code to check software packages before installing them. The tool extracts hidden installation scripts and sends them to an outside AI service called TypeSafe. You need an access key from TypeSafe to connect the software. Without a key, the tool uses an offline simulator instead.

The service returns a decision to allow, warn, or block the package. It blocks commands marked dangerous, but this does not guarantee complete safety. If the system is uncertain, it waits for a person to decide. Keep in mind that your raw scripts are sent over the internet to TypeSafe.

Keep this for later

Sign in to bookmark experiments, guides and videos, and keep notes only you can see.

Continue to sign in

We’ll bring you back to this listing.