Scan New Dependencies for Typosquatting Attacks
A single typosquatted package name in a pull request can inject malware into your build. Scan new dependencies in PRs against known-good names and flag suspicious near-matches.
- 1
Watch Dependency Changes
Add a
GitHub Triggeron PRs modifying package manifests. - 2
Check the New Packages
Add a step comparing added packages against popular-package names and your known-good list.
- 3
Judge Suspicious Names
Add an
OpenAInode flagging near-misses of popular packages and other red flags. - 4
Flag for Review
Add a
Slacknode surfacing suspicious dependencies to the reviewer. - 5
Activate and Test
Activate the workflow with a typosquat test package. Confirm it's flagged.
Frequently asked questions
Why is this a real threat?
Typosquatting is a documented supply-chain attack vector — a name one letter off can be pure malware.
False positives?
Flag for human review rather than blocking — a reviewer confirms legitimate new dependencies quickly.
Keep every recipe free
FlowRecipesHub is free and always will be. If a workflow saved you time, chip in what you like — it helps us keep the lights on and build the next batch of automations for everyone.
Secure checkout via Paddle · one-time, no account needed
