Feed aggregator
Show HN: PMG, open source package firewall
Hi HN
I am the founder of SafeDep. We have been detecting malicious packages for a while. Coming from DevSecOps background, I always considered malicious package detection & protection to be a build stage problem. But I was wrong since the S1ngularity and early Shai-Hulud days.
In 2026, we pretty much started worrying more about our own dev machines than CI/CD environment. Depending only on threat intelligence data (OSV / SafeDep / Socket / any other source) to protect our own dev machines did not feel right. We wanted to build a multi-layered protection that can get 100% visibility of OSS packages coming in, and can protect against known and “hopefully” unknown threats. That’s how Package Manager Guard (PMG) started. Core idea was simple:
- Start a local proxy (localhost)
- Make sure supported package managers like npm, pnpm, pip etc. goes through it
- Use threat intelligence data to fail fast on known malicious packages
- Apply policies like dependency cooldown as additional guardrails
- Adopt a policy language like CEL to support custom policies (roadmap)
- Everything stays local with stackable policies and audit log
- Threat model - Protect “willing” developers against malicious open source packages
Note: PMG does not consider a malicious developer as part of its threat model. So no real effort has been put to “enforce”, rather the goal is reduced friction while being effective.
Then came across Anthropic’s SRT and suddenly realized that in-process OS-native sandboxing is a good solution for limiting blast radius against unknown threats, especially since package managers have predictable runtime behaviour that can be allowed via. a sandbox while denying larger user permissions. Adopted seatbealt on MacOS and Landlock + Seccomp BPF for Linux. Seccomp BPF with Go was a battle of its own due to lack of control on OS threads, but finally managed to get it working without major performance cost.
To summarize, PMG does not only depend’s on SafeDep’s ability to find malicious packages. It enforces dependency cooldown (useful if you are stuck with older npm/pnpm), sandbox to protect against malicious packages. Our near term goal is to support CEL as a policy language and improve tooling around sandbox rules to make adoption easier.
Any feedback is welcome.
Comments URL: https://news.ycombinator.com/item?id=48994997
Points: 1
# Comments: 0
Show HN: Cross-Harness self hosted registry and analytics for AI Agents
Article URL: https://github.com/Observal/Observal
Comments URL: https://news.ycombinator.com/item?id=48994984
Points: 6
# Comments: 0
Show HN: Polymm – the Polymarket market-making bot behind my $5k wallet
Article URL: https://github.com/kachence/polymm
Comments URL: https://news.ycombinator.com/item?id=48994970
Points: 2
# Comments: 1
Stop funding data governance, run it with agents instead
Article URL: https://futuregrade.substack.com/p/stop-funding-data-governance-start
Comments URL: https://news.ycombinator.com/item?id=48994967
Points: 2
# Comments: 0
Regular Expressions for Hcpcs Codes
Article URL: https://www.johndcook.com/blog/2026/07/17/regular-expressions-for-hcpcs-codes/
Comments URL: https://news.ycombinator.com/item?id=48994964
Points: 2
# Comments: 0
Locally everywhere does not imply everywhere
Article URL: https://www.johndcook.com/blog/2026/07/21/jacobian-conjecture/
Comments URL: https://news.ycombinator.com/item?id=48994960
Points: 1
# Comments: 0
Martin Picard's Mitochondrial Theory of Mind
Article URL: https://www.quantamagazine.org/martin-picards-mitochondrial-theory-of-mind-20260717/
Comments URL: https://news.ycombinator.com/item?id=48994958
Points: 1
# Comments: 0
University of Tennessee sues Anthropic over neural network technology
Judge Pauses Paramount-Warner Bros Merger
Show HN: Serve-avd – stream any Android emulator to the browser with one command
Article URL: https://github.com/hsandhu/serve-avd
Comments URL: https://news.ycombinator.com/item?id=48994340
Points: 1
# Comments: 0
55M unique email addresses affected in Suno data breach
Article URL: https://haveibeenpwned.com/Breach/Suno
Comments URL: https://news.ycombinator.com/item?id=48994326
Points: 1
# Comments: 0
GE Aerospace flies hybrid-electric propulsion above 30k feet
The Long Road to Bottomless Postgres: Neon, Pg_mooncake, Pg_tier, Pg_lake
Article URL: https://www.pgedge.com/blog/the-long-road-to-bottomless-postgres
Comments URL: https://news.ycombinator.com/item?id=48994307
Points: 1
# Comments: 0
Building Noodle, a keyboard-first REST client for the terminal
Article URL: https://www.indiehackers.com/post/building-noodle-a-keyboard-first-rest-client-for-the-terminal-d99a1411dc
Comments URL: https://news.ycombinator.com/item?id=48994302
Points: 1
# Comments: 0
Quoting Sam Altman
Article URL: https://simonwillison.net/2026/Jul/20/sam-altman/
Comments URL: https://news.ycombinator.com/item?id=48994248
Points: 1
# Comments: 0
Hackers exploiting recently patched WordPress bugs, websites at risk
A Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims’ Blind Spots
Show HN: I rebuilt my 2000s polling site with an AI running the editorial desk
Article URL: https://groundbeat.com
Comments URL: https://news.ycombinator.com/item?id=48994216
Points: 2
# Comments: 0
The Keeper [video]
Article URL: https://vimeo.com/1153646975
Comments URL: https://news.ycombinator.com/item?id=48994213
Points: 2
# Comments: 0
