Docs / source reviewed
pkg-gate
Inspect npm lifecycle scripts before installation
How this project uses Jev
- Input
- Install hooks from a package manifest or a supplied shell script
- Jev decides
- Script intent, sensitive-resource access probabilities and potential risk
- Code executes
- Code combines risk and confidence thresholds into an allow, warn or block report for the caller’s execution policy
Evidence and limitations
A missing API key or an API failure triggers an offline simulator; its output is not a real Jev result. Evaluating supplied scripts is not a complete supply-chain audit. Detection rates were not tested here.
This project has not been run independently here. Author-reported results are not independently verified results.