Skip to content
nerlo.ai

The scanner suite

nerlo-multi-source

Nerlo-original

Nerlo-original source-versus-package provenance diff across every distribution surface.

What it scans

Every distribution surface we can acquire without executing anything — the git source repository, GitHub release assets, the npm tarball, the PyPI wheel — each read statically and diffed against the others. An artifact that publishes nothing beyond its source is reported as not applicable rather than as a pass.

What it catches

Source and provenance

Nerlo pins and publishes each scanner's provenance so you can verify it yourself. Every scan surfaces the source, version, and install command in its report.

Kind
Nerlo-original
Source channel
Nerlo-original (built in-house)
Pinned version
shipped in the deployed pipeline
License
Nerlo
Source URL
https://github.com/nerlo-ai/nerlo-canary-fakegit