ForgeGuardian was built in order to discover the threats that software supply chain has other than those detected by the regular CVE scanning process.
2. What problem it solves Include:
Malicious packages Typosquatting Dependency attacks Behavioral threats Malware Threats related to AI/MCP
3. What you actually built This includes:
8 detection engines 9 ecosystems More than 223 detection signatures CLI/web dashboards Offline/local-first functionality SBOM Policy enforcement CI/CD Webhooks Prevention/quarantine
4. What you want HN users to look at This is crucial. Ask a legitimate technical question, e.g.:
I would be most interested in hearing feedback about the detection mechanism and what you see as the weaknesses of supply-chain scanners. I would also love to get your opinion on the signature model and false positives management.