OSPulse

Notes on keeping open source healthy and trustworthy.

The OSPulse blog is where we share what we learn watching the open-source supply chain — the attacks, the drift, and the signals that separate a safe dependency from a liability. The first articles are on their way.

What we write about

Supply-chain attacks, dissected

Post-mortems of real incidents — event-stream, ua-parser-js, xz-utils, polyfill.io — and what signals would have flagged them before a CVE ever existed.

Dependency drift

Why the packages you shipped last year quietly become your biggest risk: abandonment, maintainer churn, and the slow rot that scanners never report.

Reading the health of open source

How we score maintenance, momentum, and risk across npm, PyPI, and beyond — and how to read those signals when you choose a dependency.

Regulation & the CRA

Practical guidance for engineering teams preparing for the EU Cyber Resilience Act and tightening expectations around software bills of materials.

Engineering at OSPulse

How we ingest 10+ threat feeds, traverse enormous dependency graphs, and turn noisy intelligence into a single, actionable signal.

Field notes

Shorter takes on the tooling, papers, and incidents shaping how modern teams secure their open-source estate.

While you wait

The most useful thing we can show you is your own dependency tree. See which of your packages would start a CRA Article 14 clock — free, nothing to install.