General
NPM Supply-Chain Risk Graph with Statistical Scoring
npm-sentinel analyses packages for vulnerabilities, maintenance health, and license risks; -code-interpreter computes statistical risk scores (CVSS aggregation, maintenance decay curves, license compatibility matrices) in Python; neo4j-cypher stores the scored dependency graph for traversal queries. The product produces a continuously updated, statistically rigorous supply-chain risk map that security teams can query by blast radius, risk score, or license type.
Tools connected
- Docker
What it automates
raw_risk_signals → -code-interpreter.compute_risk_scores → scored_nodes → neo4j-cypher.write_graph + cypher_traversal_query
Want this one built?
Schedule it and we'll build it in the next 24 hours — you'll get an email the moment it goes live.