Skip to content

Repository files navigation

Citara

A framework to introspect NPM packages

Citara is a highly extensible framework for analyzing NPM packages to enforce strict security, compliance and quality standards across your dependency tree.

It provides the building blocks to inspect, evaluate and enforce policies on packages before they enter your software supply chain.

Motivation

NPM is one of the largest software ecosystems in the world and a frequent target for supply chain attacks. Malicious packages can introduce vulnerabilities long before code ever reaches production

At the same time, the rise of AI-assisted development is dramatically increasing the rate at which new dependencies enter codebases. AI tools frequently select and introduce packages with little scrutiny, amplifying supply chain risks.

Citara provides automated guardrails for this new development model ensuring that packages, whether chosen by humans or AI, meet strict security and quality standards before entering your codebase.

About

A framework to introspect NPM packages

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages