Stop guessing which dependency will bite you.

Scan any repository and see exactly which of your services resolve a compromised version, and when you were exposed.

Powered byHydraDB
Supply chain visualization
GET /api/investigate/npm/lodash/4.17.20

contacting HydraDBโ€ฆ

Recent CVEs

See it in action

Everything you need to catch a compromised dependency.

actik dashboard

Open source first

Point it at a public repository.

Paste a link and actik reads the lockfiles, resolves the exact versions, and traces which of your services would be exposed.

Scan a repository

Currently works with GitHub and GitLab public repositories only.

โ€œThe moral is obvious. You can't trust code that you did not totally create yourself. No amount of source-level verification or scrutiny will protect you from using untrusted code.โ€

KT

Ken Thompson

B, Unix, UTF-8, Go and Turing Award 1983

Reflections on Trusting Trust, 1984 Turing Award Lecture

Sounds relatable?

Scan a repository

FAQ

Common questions

Ask AI

Still not sure?

Don't just take our word for it. See what your favorite AI says about actik.

Catch the next worm before it spreads.

Scan any repository and know exactly which of your services are exposed, the moment a package is compromised.

Scan a repository