git-pkgs tracks package dependencies across your repository's git history. It answers questions like "who added this dependency?", "when was it introduced?", and "how long were we exposed to this vulnerability?" Works with 45+ package managers.
Install it with:
brew install git-pkgsOr download a binary from the releases page.
Or build from source:
go install github.com/git-pkgs/git-pkgs@latest- brief - Detect a project's toolchain, configuration, and conventions
- capcheck - Fail CI when Go code or dependencies gain new privileged operations
- distill - Train and run repository classifiers from code-derived signals
- downstream - Test library changes against projects that depend on them
- forge - Work with GitHub, GitLab, Gitea, Forgejo, Bitbucket, Gerrit, and Tangled through one CLI
- git-pkgs - Track package dependencies across a repository's git history
- licenses - Scan repositories for license text using ScanCode's rule corpus
- pin - Vendor browser assets without npm
- proxy - Lightweight caching proxy for package registries
- silo - Prototype Git host with gittuf verification in the receive path
- actions - Reusable GitHub Actions for git-pkgs dependency analysis
- skills - Claude Code skills plugin for git-pkgs, brief, forge, pin, and capcheck
Identity & versions
- purl - Package URL construction, parsing, and registry URL mapping
- vers - Version range parsing and comparison per the VERS spec
- platforms - Translating platform identifiers across package ecosystems
- artifacts - Describing package files with package URLs, content digests, and byte counts
Manifests & resolution
- manifests - Parsing package manager manifest and lockfiles
- managers - Wrapping package manager CLIs behind a common interface
- resolve - Parsing package manager resolve output into dependency trees
- pom - Resolving effective POMs for Maven artifacts
Data sources
- registries - Fetching package metadata from registry APIs
- enrichment - Fetching package metadata from multiple sources
- vulns - Fetching vulnerability data from multiple sources
- nexus - Reading Maven repository indexes without Java or Lucene
- cooldown - Filtering package versions by minimum age across ecosystems
Provenance
- attestation - Parsing SLSA provenance v1 attestation bundles
- sigstore - Verifying attestation bundles against the Sigstore TUF trust root
- integrity - Parsing Subresource Integrity metadata and verifying streams
Formats
- sbom - Reading and writing Software Bill of Materials documents
- sarif - Reading, writing, and validating SARIF 2.1.0 logs
- cwe - Looking up MITRE CWE entries and categories
Licensing
- licenses - Matching license text against ScanCode's rule corpus
- reuse - Extracting SPDX license and copyright data from REUSE-compliant projects
- spdx - SPDX license expression parsing, normalization, and validation
Files & content
- archives - Reading and browsing archive files in memory
- changelog - Parsing changelog files into structured entries
- gitignore - Matching paths against gitignore rules
- magic - Detecting file formats and MIME types from content
- markup - Rendering markup files to HTML
Source & repository
- clone - Managing local checkouts of remote Git repositories
- dependents - Finding and ranking repositories that depend on a package
- outline - Reduce a source tree to a structural skeleton for LLM context
- provides - Mapping package identities to names used in source code
Storage
- gcs - Minimal Google Cloud Storage client over the JSON API