Depfu continuously updates your dependencies one at a time and creates a pull request with all the info you need. You stay in control.
Cost / License
- Free Personal
- Proprietary
Platforms
- Online



Libraries.io is described as 'Discover open source libraries to use in your software projects and be notified of new releases to keep your applications up to date and secure' and is an website in the development category. There are more than 10 alternatives to Libraries.io, not only websites but also apps for a variety of platforms, including Windows, Self-Hosted, Linux and SaaS apps. The best Libraries.io alternative is GitHub, which is free. Other great sites and apps similar to Libraries.io are Patchdex, NewReleases, Aikido Security and Proscan AppSec.
Depfu continuously updates your dependencies one at a time and creates a pull request with all the info you need. You stay in control.



NPMScan is a security analysis tool for the JavaScript ecosystem. It scans npm packages for malicious behavior and supply chain risks that are often invisible to developers. The scanner inspects scripts, dependencies, encoded payloads, metadata, and common attack patterns used...




SkillRisk is a specialized security analysis tool designed for the AI Agent ecosystem, specifically focusing on Claude Code and Model Context Protocol (MCP) skills.




Software updates straight to your inbox. Touchpine monitors your applications and libraries - you no longer need to subscribe to dozens of security mailing lists to watch for software updates. Touchpine delivers fully customized notifications to your email.



PackageFix is a free browser-based dependency security fixer. Paste your manifest file and get back a fixed version with every vulnerable package patched — ready to download in one click.



Get notified by a email and a push notification every time a new release of your repository is available.
Dependency Update Automation for npm, composer and docker made easy. Check your git repositories for vulnerabilities now!.



