Phylum

Phylum ⦾ The Software Supply Chain Security Company

Phylum scans packages in open-source repositories, identifying threats, risks and supply chain attacks. We build tools to help developers and the organizations they work for block attacks, malware, and vulnerabilities from entering their software development lifecycle.

😄 Sign-up for a free Phylum account and start identifying and blocking risks in your software projects.

🔧 Open-Source Projects

Phylum CLI

The Phylum CLI provides direct access to the Phylum platform. Create and submit project lockfiles/manifest files (e.g., package-lock.json, requirements.txt, etc.)

Birdcage (Cross-platform Execution Sandbox)

A cross-platform sandbox used in the Phylum CLI to provide a locked down environment for package installation.

🌐 Find Us Online

🧟‍♂️ 2023: Softare Supply Chain Attack Reporting

We have successfully identified numerous supply chain attacks. So far in 2023 we've reported on:

Pinned Loading

  1. Command line interface for the Phylum API

    Rust 107 11

  2. GitHub Action to analyze Pull Requests for open-source supply chain issues

    16 2

  3. Cross-platform embeddable sandboxing

    Rust 210 11

  4. GitHub Action to install phylum CLI tool

    1

  5. A collection of community extensions for the Phylum CLI

    TypeScript 1 1

  6. Python package for handling CI and other integrations

    Python 10 1

Repositories

Type
Select type

Language
Select language

Sort
Select order

Showing 10 of 26 repositories

  • phylum-dev/documentation’s past year of commit activity

    JavaScript

    1 2 11 0

    Updated Mar 26, 2026

  • phylum-ci Public

    Python package for handling CI and other integrations

    phylum-dev/phylum-ci’s past year of commit activity

    Python

    10

    GPL-3.0

    1 11 0

    Updated Mar 23, 2026

  • cli Public

    Command line interface for the Phylum API

    phylum-dev/cli’s past year of commit activity

  • purl Public

    Package URL implementation for Rust

    phylum-dev/purl’s past year of commit activity

    Rust

    14

    MIT

    1 1 0

    Updated Dec 8, 2025

  • birdcage Public

    Cross-platform embeddable sandboxing

    phylum-dev/birdcage’s past year of commit activity

    Rust

    210

    GPL-3.0

    11 4 2

    Updated Nov 24, 2025

  • phylum-dev/phylum-analyze-pr-action’s past year of commit activity

    16

    GPL-3.0

    2 0 0

    Updated Nov 4, 2025

  • vuln-reach Public archive

    A library for building tools to determine if vulnerabilities are reachable in a code base.

    phylum-dev/vuln-reach’s past year of commit activity

    Rust

    17

    Apache-2.0

    1 20 0

    Updated Aug 19, 2025

  • phylum-dev/.github’s past year of commit activity

    0 0

    0 0

    Updated Aug 18, 2025

  • phylum-dev/changes-stream-rust’s past year of commit activity

    Rust 0 MIT

    7 0 0

    Updated Apr 10, 2025

  • purl-survey Public

    Package URL implementation test harness

    phylum-dev/purl-survey’s past year of commit activity

    Python

    5 1 0 0

    Updated Mar 19, 2025