Refuse sits in front of npm, pip, cargo, gem, go + 13 more package managers and refuses known-vulnerable installs before they hit disk — the moment you (or your coding agent) run them. Also, Open-source, self-hostable, one Docker container.
Refuse is a security tool that prevents the installation of known-vulnerable packages across multiple package managers, including npm and pip. It is open-source, self-hostable, and deployable via a single Docker container.