Solutions

Establish trust in the expanded software supply chain

Know what you depend on, keep bad components out, and respond fast when one turns bad.

Compromised dependencyUrgent

The challenge

Can we trust what our software pulls in?

Prevent

Bad components kept out.

Checks in the agent, in CI and at the pull request stop risky packages before they merge.

Safe versions picked in the agent
Malicious packages caught in CI
Compromised, unpinned and too-new dependencies held at the PR
PR #318 · Update loggingTier 1
RuleModeResult
Compromised Dependencydebug 4.4.2
BlockFailed
Unpinned Dependencyactions/checkout@v4
WarnFlagged
Dependency Version Minimum AgeBlockPassed
Blocked: 1 compromised dependency
Posture

What you depend on, scored.

Heeler checks your repositories, pipelines, images and agent tooling for the weak spots attackers use.

OpenSSF Scorecard on every repository
Unpinned actions in your pipelines
Base images past end of support
Supply chain posture · acme4 to harden
ComponentResultFrom
acme/ordersOpenSSF Scorecard
5.8 / 10SCA
actions/checkout@v4.github/workflows/deploy.yml
Not pinned to a commitCI/CD pipelines
node:16-alpineorders-api image
Past end of supportContainer images
deploy-helper skill.claude/skills
SuspiciousCoding agents
When one turns bad

Compromised is always Urgent.

When a package you run turns bad, the owner gets a ticket and an upgrade PR to a known-good version.

Found in every repository that runs it
Ticket to the owning team
Upgrade PR, checked again at the PR