nerlo-multi-source
Nerlo-originalNerlo-original source-versus-package provenance diff across every distribution surface.
What it scans
Every distribution surface we can acquire without executing anything — the git source repository, GitHub release assets, the npm tarball, the PyPI wheel — each read statically and diffed against the others. An artifact that publishes nothing beyond its source is reported as not applicable rather than as a pass.
What it catches
- Behaviour in a published package that is absent from the tracked source — the postmark-mcp supply-chain-divergence shape.
- Malware findings on a release asset or published tarball that a source-only scan never opens — the FakeGit release payload.
- A published surface whose own verdict is worse than the source's; each surface keeps its own score rather than being averaged away.
Source and provenance
Nerlo pins and publishes each scanner's provenance so you can verify it yourself. Every scan surfaces the source, version, and install command in its report.
- Kind
- Nerlo-original
- Source channel
- Nerlo-original (built in-house)
- Pinned version
- shipped in the deployed pipeline
- License
- Nerlo
- Source URL
- https://github.com/nerlo-ai/nerlo-canary-fakegit