App category

Developer and software supply chain

Check the package, manifest, dependency, and integration details around a software release. These apps inspect npm readiness, vulnerable JavaScript, SBOMs, deep links, web app manifests, workflow files, security headers, and connected-device metadata.

Choose an app when

  • Use npm Package Check for the published tarball and release metadata; use JS Vulnerability Check for library versions served by a public page.
  • Use SBOM Check for CycloneDX or SPDX documents and CWL Workflow Check for workflow resolution and step wiring.
  • Use Web App Manifest Check for web app installability, Deep Link Check for iOS and Android association files, and Thing Description Check for a WoT document.
  • Use Security Headers Check for browser protection headers and Auth Discovery Check for OIDC or OAuth discovery.