Drydock is open source, Apache-2.0. It reviews the package artifact you’re about to publish. The built tarball, diffed against the last published version, with install scripts and new binaries pinned to the lines that changed. You make the call. github.com/JoviDeCroock/drydock
GitHub - JoviDeCroock/drydock: Review the artifact before you publish it: diffs the built npm/PyPI package against the last published version and pins risk signals to the changed lines
Review the artifact before you publish it: diffs the built npm/PyPI package against the last published version and pins risk signals to the changed lines - JoviDeCroock/drydock
github.com