Skip to content

Private preview

Dendra

A credit rating for the code you depend on

Most of your software is code you didn’t write. Dendra grades every package you depend on — the ones you picked and the ones they brought along — and shows you the evidence behind each grade.

Request accessDendra is in private preview.

What Dendra does

When you install one package, you install everything it needs, and everything those need. Most teams only look at the packages they chose. Dendra grades all of them.

A grade, and the reasons for it

Every package gets a grade from A to F, built from the public record: known security problems, how fast fixes arrive, whether anyone still maintains it, whether its releases can be trusted, and what it brings with it. Every grade opens to the facts behind it — the advisory, the date, the release.

Everything installed, not just what you chose

The packages you chose are the small part. Dendra maps everything they bring with them and shows where the risk really sits — often a small, quiet package that most of your build depends on.

See it on a real package. This is Dendra’s risk rings for express 4.18.2, graded in private preview. The centre is what you chose; each ring out is what that brought with it. Choose any dot for its evidence, and use the two buttons to show everything installed or to trace attack paths — how a problem deep in the tree could reach you.

Try it:

What you are looking at

The 21 packages your team chose — the list most teams believe they are managing.

Why it matters

Two of these branches already hide a package graded D, and nothing at this level tells you which one. The risk you can see is not the risk you carry.

express v4.18.2 — grade DDexpress71 packages in the treedebug v2.6.9 — grade DDes-errors v1.3.0 — grade BBfunction-bind v1.1.2 — grade BBcall-bind-apply-helpers v1.0.2 — grade AAgopd v1.2.0 — grade AAdunder-proto v1.0.1 — grade AAescape-html v1.0.3 — grade BBes-define-property v1.0.1 — grade AAmath-intrinsics v1.1.0 — grade AAget-proto v1.0.1 — grade AAes-object-atoms v1.1.2 — grade AAhas-symbols v1.1.0 — grade AAobject-inspect v1.13.4 — grade AAasync-function v1.0.0 — grade AAhasown v2.0.4 — grade AAasync-generator-function v1.0.0 — grade AAee-first v1.1.1 — grade BBget-intrinsic v1.3.1 — grade AAcall-bound v1.0.4 — grade AAsetprototypeof v1.2.0 — grade BBgenerator-function v2.0.1 — grade AAencodeurl v1.0.2 — grade BBdepd v2.0.0 — grade BBdepdon-finished v2.4.1 — grade BBtoidentifier v1.0.1 — grade BBside-channel-map v1.0.1 — grade AAstatuses v2.0.1 — grade AAinherits v2.0.4 — grade BBdestroy v1.2.0 — grade BBside-channel-weakmap v1.0.2 — grade AAms v2.0.0 — grade AAside-channel-list v1.0.1 — grade AAhttp-errors v2.0.0 — grade AAetag v1.8.1 — grade BBetagqs v6.11.0 — grade AAqs21 insidesend v0.18.0 — grade AAsend16 inside · worst: Dms v2.1.3 — grade AAfresh v0.5.2 — grade AAsafer-buffer v2.1.2 — grade DDside-channel v1.1.1 — grade AAmime v1.6.0 — grade AAunpipe v1.0.0 — grade BBpath-to-regexp v0.1.7 — grade DDpath-to-regexpparseurl v1.3.3 — grade BBparseurlbytes v3.1.2 — grade BBsafe-buffer v5.2.1 — grade BBsafe-buffermime-db v1.52.0 — grade AAforwarded v0.2.0 — grade BBmedia-typer v0.3.0 — grade AAcontent-type v1.0.5 — grade AAmime-types v2.1.35 — grade AAnegotiator v0.6.3 — grade AAutils-merge v1.0.1 — grade BButils-mergearray-flatten v1.1.1 — grade BBarray-flattenmerge-descriptors v1.0.1 — grade BBmerge-descriptorscookie-signature v1.0.6 — grade BBcookie-signaturevary v1.1.2 — grade BBvarymethods v1.1.2 — grade BBmethodsproxy-addr v2.0.7 — grade BBproxy-addr2 insidebody-parser v1.20.1 — grade AAbody-parser6 inside · worst: Draw-body v2.5.1 — grade AAserve-static v1.15.0 — grade AAserve-staticiconv-lite v0.4.24 — grade AAaccepts v1.3.8 — grade AAaccepts3 insidecookie v0.5.0 — grade AAcookierange-parser v1.2.1 — grade AAtype-is v1.6.18 — grade AAtype-is1 insideipaddr.js v1.9.1 — grade AAfinalhandler v1.2.0 — grade AAfinalhandlercontent-disposition v0.5.4 — grade AAcontent-disposition

Real Dendra output, npm · as of 9 July 2026

What to fix first

Dendra lists what to fix first: the packages where one update removes the most risk, and how many other packages that update helps. Where a safer package does the same job, it names it.

Unknown is not safe

When Dendra can't check something, it says so and counts it as a risk. It never assumes a package is fine because nobody has looked. Grades were tested on packages already known to be bad; they do not predict future problems.

For audits

Bring a CycloneDX or SPDX SBOM — or just a package.json — and get it back with every package graded, plus an OpenVEX record of what was assessed and what you set aside. Write your rule once — for example, nothing graded D or F anywhere in the tree — and Dendra tells your build whether it passes. Everything exports as a dated audit pack, with the evidence annotated against S2C2F, NIST SSDF and the EU Cyber Resilience Act, whose reporting duties begin on 11 September 2026.

SBOMVEXS2C2FSSDFEU-CRA

What it covers today

npm, in depth. Other registries run on the same interface and follow: PyPI, Maven and Gradle, Go, NuGet, SwiftPM and CocoaPods, Cargo, vcpkg and Conan.

npm — in previewPyPIMaven / GradleGo module proxyNuGetSwiftPM / CocoaPodsCargovcpkg / Conan

How Dendra grades

Who it’s for

Engineering and security leads who need to answer two questions: what are we built on, and what should we do about it.

Dendra is in private preview.