Ghost Libraries
The 1,000 most-used packages from each of PyPI, Maven Central, and npm. Each one scanned, with binary provenance analysis and a report you can hand to your ISSM.
| Rank | Package | Registry | Latest | Scan | Provenance | Report |
|---|---|---|---|---|---|---|
| #1 |
boto3
The AWS SDK for Python
|
PyPI | 1.43.82 | Scanned | Checked | View report |
| #1 |
junit:junit
JUnit is a unit testing framework for Java, created by Erich Gamma...
|
Maven Central | 4.13.2 | Scanned | Checked | View report |
| #1 |
semver
The semantic version parser used by npm.
|
npm | 7.8.5 | Scanned | Checked | View report |
| #2 |
packaging
Core utilities for Python packages
|
PyPI | 26.3 | Scanned | Checked | View report |
| #2 |
org.springframework.boot:spring-boot-starter-test
Starter for testing Spring Boot applications with libraries including...
|
Maven Central | 4.1.1 | Scanned | Checked | View report |
| #2 |
debug
Lightweight debugging utility for Node.js and the browser
|
npm | 4.4.3 | Scanned | Checked | View report |
| #3 |
typing-extensions
Backported and Experimental Type Hints for Python 3.9+
|
PyPI | 4.16.0 | Scanned | Checked | View report |
| #3 |
org.springframework.boot:spring-boot-starter-web
Starter for building web, including RESTful, applications using...
|
Maven Central | 4.1.1 | Scanned | Checked | View report |
| #3 |
minimatch
a glob matcher in javascript
|
npm | 10.2.6 | Scanned | Checked | View report |
| #4 |
certifi
Python package for providing Mozilla's CA Bundle.
|
PyPI | 2026.7.22 | Scanned | Checked | View report |
| #4 |
mysql:mysql-connector-java
No description published
|
Maven Central | 8.0.33 | Scanned | Checked | View report |
| #4 |
ansi-styles
ANSI escape codes for styling strings in the terminal
|
npm | 7.0.0 | Scanned | Checked | View report |
Each package is scanned for published CVEs, with the results in the report.
Does the binary you pull match what the source says it should be? We look before it lands in your build.
Findings written up in a format your accreditation team can use. Not a raw scanner dump.
Tell us what your programs pull. We will tell you if it is covered, or when it will be. Or email boo@seeghost.dev.