Ghost by AlphaBravo Get a price

Ghost Libraries

3,000 packages. Checked before you pull them.

The 1,000 most-used packages from each of PyPI, Maven Central, and npm. Each one scanned, with binary provenance analysis and a report you can hand to your ISSM.

PyPInpmMaven
Registry
Rank Package Registry Latest Scan Provenance Report
#1
boto3 The AWS SDK for Python
PyPI 1.43.82 Scanned Checked View report
#1
junit:junit JUnit is a unit testing framework for Java, created by Erich Gamma...
Maven Central 4.13.2 Scanned Checked View report
#1
semver The semantic version parser used by npm.
npm 7.8.5 Scanned Checked View report
#2
packaging Core utilities for Python packages
PyPI 26.3 Scanned Checked View report
#2
org.springframework.boot:spring-boot-starter-test Starter for testing Spring Boot applications with libraries including...
Maven Central 4.1.1 Scanned Checked View report
#2
debug Lightweight debugging utility for Node.js and the browser
npm 4.4.3 Scanned Checked View report
#3
typing-extensions Backported and Experimental Type Hints for Python 3.9+
PyPI 4.16.0 Scanned Checked View report
#3
org.springframework.boot:spring-boot-starter-web Starter for building web, including RESTful, applications using...
Maven Central 4.1.1 Scanned Checked View report
#3
minimatch a glob matcher in javascript
npm 10.2.6 Scanned Checked View report
#4
certifi Python package for providing Mozilla's CA Bundle.
PyPI 2026.7.22 Scanned Checked View report
#4
mysql:mysql-connector-java No description published
Maven Central 8.0.33 Scanned Checked View report
#4
ansi-styles ANSI escape codes for styling strings in the terminal
npm 7.0.0 Scanned Checked View report
Showing 12 of 3,000 packagesPyPI and npm ranked by monthly downloads. Maven Central ranked by dependent repositories, since it does not publish download counts. Load more

What the ghost checks in every package.

Known vulnerabilities

Each package is scanned for published CVEs, with the results in the report.

Binary provenance

Does the binary you pull match what the source says it should be? We look before it lands in your build.

A report you can hand over

Findings written up in a format your accreditation team can use. Not a raw scanner dump.

Need a package that is not on the list?

Tell us what your programs pull. We will tell you if it is covered, or when it will be. Or email boo@seeghost.dev.

Talk to us