Catch a supply-chain attack before it ships.
postmortem reads the code you install and the history of who publishes it. Malicious install scripts, typosquats, hijacked maintainer accounts, all flagged before your build runs them. One binary, offline by default.
The attack was visible before the payload.
In 2018 an attacker asked the maintainer of event-stream for publish rights, got them, and shipped a harmless release to look legitimate. That release is the tell: a new publisher, after 779 days of silence. postmortem flags it from the registry history alone, no malware signature needed.
$ postmortem timeline event-stream 2018-09-05 ! 3.3.5 publisher changed dominictarr → right9ctrl released after 779d of silence 2018-09-09 ! 3.3.6 unpublishedRead all 11 replays, misses included →
A CVE scanner finds bugs. This finds intent.
Two examinations on every dependency: what its code does when you install it, and what changed in the way it gets published.
In the code
postmortem scan · fully offlineIn the history
postmortem tree --online · registry metadata onlyOne binary. Every question about your dependencies.
Each subcommand answers one question, and every one of them speaks JSON for your scripts.
Malicious code in what you install, or inside a container image. SARIF and HTML reports.
The dependency graph with reputation and provenance. --human shows who controls what.
One graded verdict covering malware, risk and CVEs.
Publisher handovers, install scripts appearing, repository moves, unpublished versions.
An attack is announced: were you ever exposed, where, and since which commit?
What a branch or a GitHub pull request adds to your dependency tree.
Why a package is installed, and what a compromise of it would reach.
Every dependency that runs code at install time, approved or pending.
The same audit for the packages installed on the machine itself.
The smallest upgrade that clears the known CVEs.
License policy with allow and deny lists, CycloneDX 1.5 export.
A git pre-commit hook, or a re-scan each time a lockfile changes.
Your lockfiles, and the machine they run on.
Point it at a project folder and it finds every lockfile on its own. Point system at a laptop or a server and it reads what the package managers installed.
Seven ecosystems, plus sources
Linux, macOS, Windows
Gate the build. Keep the code.
Built to sit in a pipeline and say no, without sending your source anywhere.
Fails closed
Exit 1 above your threshold, 2 on error, and 2 as well when a check could not run. SARIF lands in code scanning; postmortem ci writes the pipeline for GitLab, Azure DevOps and Jenkins.
# .github/workflows/postmortem.yml - uses: mlab-sh/[email protected] with: online: true vulns: true
Nothing leaves by default
No telemetry, no daemon, no account.
- scan · tree · system
fully offline - --online · --vulns
package names and versions only, never your code - proxy · CA · mirrors
built for locked-down networks
From finding to intel
Standalone by design. Connected to mlab.sh, it goes further.
- --vulns
CVE, GHSA and OSV matching via vuln.mlab.sh - --enrich
every IOC in a report links to its mlab.sh analysis - Claude Code
supply-chain audit and dependency vetting skills
Ready in one minute.
Prebuilt for macOS, Linux and Windows on x86_64 and arm64. Then run postmortem scan . at the root of a repository.
brew tap mlab-sh/postmortem https://github.com/mlab-sh/postmortem.git
brew install postmortem
sudo install -m 0755 -d /etc/apt/keyrings
sudo curl -fsSL https://apt.mlab.sh/postmortem.asc -o /etc/apt/keyrings/postmortem.asc
sudo tee /etc/apt/sources.list.d/postmortem.sources >/dev/null <<'EOF'
Types: deb
URIs: https://apt.mlab.sh
Suites: stable
Components: main
Architectures: amd64 arm64
Signed-By: /etc/apt/keyrings/postmortem.asc
EOF
sudo apt update && sudo apt install postmortem
scoop bucket add postmortem https://github.com/mlab-sh/postmortem.git
scoop install postmortem
git clone https://github.com/mlab-sh/postmortem.git
cd postmortem
cargo install --path .