Thirdpass

Coordinated supply chain review.

Thirdpass directs review effort toward package artifacts that need coverage, records structured findings, and lets projects check their dependencies from the terminal.

Recent Reviews

View all reviews

Showing 1 of 1 reviewed packages

PackageRegistryVersionSeverityReviews
minimistnpmjs.com1.2.8none1

How Thirdpass Builds Review Coverage

Assign review targets
The server directs review effort toward packages and files that need coverage.
Layered evidence
Reviews can cover part of a package, adding evidence without certifying the whole thing.
Check dependency coverage
Projects query accumulated review data with thirdpass check.

Quickstart

Contribute reviews and check dependency coverage from your terminal.

Help review the shared package pool:

$ thirdpass review-any

Review specific files:

$ thirdpass review d3 4.10.0 \
  --file index.js \
  --file build/d3.js

Check accumulated reviews for your dependencies:

$ thirdpass check

Designed for multiple ecosystems

Thirdpass supports dependency ecosystems through extensions.

EcosystemRegistryExtensionAvailability
Rustcrates.iothirdpass-rsBuilt in
Pythonpypi.orgthirdpass-pyBuilt in
JavaScriptnpmjs.comthirdpass-jsBuilt in
Ansible Galaxygalaxy.ansible.comthirdpass-ansibleExternal