Hipcheck โœ…'s Avatar

Hipcheck โœ…

@hipcheck.mitre.org

โš ๏ธ Identify risky open source software dependencies. ๐Ÿ”Œ Extend data sources and analyses with plugins. ๐Ÿ‘ Open source, built by MITRE, a not-for-profit. โœ… hipcheck.mitre.org ๐Ÿ’ป github.com/mitre/hipcheck

20 Followers  |  1 Following  |  14 Posts  |  Joined: 22.10.2024  |  1.3509

Latest posts by hipcheck.mitre.org on Bluesky

It's true, we document how to debug Hipcheck!

Hipcheck exists to empower software devs to make informed OSS dependency choices, and we want to empower our users when something goes wrong too.

05.02.2026 22:39 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Hipcheck 3.13.0 Release Helping maintainers assess software packages for long-term risk.

Hipcheck 3.13.0 is here! ๐ŸŽ‰

โœ… Clearer reporting when we recommend "investigate" because of an "investigate-if-fail" policy.
โœ… A new "hc explain target-triple" subcommand.
โœ… Work toward supporting "multi-target" runs of Hipcheck based on files like go.mod, package-lock.json, or Cargo.lock

11.04.2025 18:57 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1
Python Plugin SDK Initial Release Helping maintainers assess software packages for long-term risk.

Announcing the Hipcheck Python Plugin SDK!

With this SDK, you can now easily create Hipcheck plugins in Python. This SDK is at full feature parity with the existing Rust SDK. Give it a try, and let us know what you think!

hipcheck.mitre.org/blog/python-...

11.04.2025 18:53 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1

On the new glibc minimum version, this is due to GitHub sunsetting support for Ubuntu 20.04 runners, and we've included a guide for still running new releases on Ubuntu 20.04 either by installing a newer glibc or building Hipcheck yourself.

18.03.2025 18:30 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Hipcheck 3.12.0 Release Helping maintainers assess software packages for long-term risk.

Hipcheck 3.12.0 is out! ๐ŸŽ‰

โœ… SemVer constraints for plugins
โœ… New flag for "hc ready"
โœ… New command to manage plugin cache
โœ… Initial support for containerized plugins
โœ… Improvements to plugin logging
๐Ÿงช An experimental Python plugin SDK!
โš ๏ธ New minimum glibc version

hipcheck.mitre.org/blog/hipchec...

18.03.2025 18:28 โ€” ๐Ÿ‘ 3    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Hipcheck 3.11.0 Release Helping maintainers assess software packages for long-term risk.

Hipcheck 3.11.0 is out! ๐ŸŽ‰

Featuring usability improvements like integrating plugins into the "hc ready" command, to be sure you're ready to run, better error reporting from plugins, improved JSON format final analysis reports, and more!

hipcheck.mitre.org/blog/hipchec...

26.02.2025 19:21 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Hipcheck's Ramp of Maximum Configurability Helping maintainers assess software packages for long-term risk.

Hipcheck offers levels of configurability to smoothly ramp up users from no-config out of the box to any level of flexibility you need!

Come learn about configuring default policies, setting custom policies, and creating your own analysis plugins!

hipcheck.mitre.org/blog/hipchec...

12.02.2025 22:21 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Plugins Helping maintainers assess software packages for long-term risk.

Last but not least, all of our first-party plugins have been upgraded to use the new SDK, so they *also* get the benefit of the query protocol improvements!

hipcheck.mitre.org/docs/guide/p...

01.02.2025 00:06 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
hipcheck_sdk - Rust Hipcheck Plugin SDK in Rust.

We also released version 0.3.1 of the Rust SDK! ๐Ÿฆ€

This includes support for the plugin protocol improvements, including new APIs for batching queries, plus a number of documentation and API structure improvements.

docs.rs/hipcheck-sdk...

01.02.2025 00:06 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Hipcheck 3.10.0 Release Helping maintainers assess software packages for long-term risk.

Hipcheck 3.10.0 is out! ๐ŸŽ‰

This release features:

โœ… Improvements to the query protocol between Hipcheck and its plugins
โœ… A new "env" macro for policy files
โœ… The start of English-language policy explanations, and more!

hipcheck.mitre.org/blog/hipchec...

01.02.2025 00:06 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 1
Hipcheck 3.9.1 Release Helping maintainers assess software packages for long-term risk.

Hipcheck 3.9.1 is out, with fixes to our Containerfile, better support for specifying custom paths in policy files, and a refactor to improve target resolution!

hipcheck.mitre.org/blog/hipchec...

09.01.2025 15:07 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1
Hipcheck 3.8.0 Release Helping maintainers assess software packages for long-term risk.

Hipcheck 3.8.0 is out! ๐ŸŽ‰ This release includes stable support for third-party plugins, plus improvements to the Rust plugin SDK.

hipcheck.mitre.org/blog/hipchec...

12.12.2024 21:43 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1
hipcheck_sdk - Rust API documentation for the Rust `hipcheck_sdk` crate.

Hipcheck is written in Rust, and we have an SDK out today to make it easier to write plugins in Rust!

We'd love to partner with anyone who's interested in making a plugin!

docs.rs/hipcheck-sdk...

#rust #rustlang

23.10.2024 19:00 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Hipcheck

Hello world!

Hipcheck is an open source project to empower maintainers to assess their dependencies.

Take 100s of dependencies down to a few that look concerning, based on your chosen plugins and configuration!

We don't force any policy; all defaults can be changed!

mitre.github.io/hipcheck/

23.10.2024 18:59 โ€” ๐Ÿ‘ 4    ๐Ÿ” 2    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

@hipcheck.mitre.org is following 1 prominent accounts