Private preview
Dendra
A credit rating for the code you depend on
Most of your software is code you didn’t write. Dendra grades every package you depend on — the ones you picked and the ones they brought along — and shows you the evidence behind each grade.
What Dendra does
When you install one package, you install everything it needs, and everything those need. Most teams only look at the packages they chose. Dendra grades all of them.
A grade, and the reasons for it
Every package gets a grade from A to F, built from the public record: known security problems, how fast fixes arrive, whether anyone still maintains it, whether its releases can be trusted, and what it brings with it. Every grade opens to the facts behind it — the advisory, the date, the release.
Everything installed, not just what you chose
The packages you chose are the small part. Dendra maps everything they bring with them and shows where the risk really sits — often a small, quiet package that most of your build depends on.
See it on a real package. This is Dendra’s risk rings for express 4.18.2, graded in private preview. The centre is what you chose; each ring out is what that brought with it. Choose any dot for its evidence, and use the two buttons to show everything installed or to trace attack paths — how a problem deep in the tree could reach you.
What you are looking at
The 21 packages your team chose — the list most teams believe they are managing.
Why it matters
Two of these branches already hide a package graded D, and nothing at this level tells you which one. The risk you can see is not the risk you carry.
Real Dendra output, npm · as of 9 July 2026
What to fix first
Dendra lists what to fix first: the packages where one update removes the most risk, and how many other packages that update helps. Where a safer package does the same job, it names it.
Unknown is not safe
When Dendra can't check something, it says so and counts it as a risk. It never assumes a package is fine because nobody has looked. Grades were tested on packages already known to be bad; they do not predict future problems.
For audits
Bring a CycloneDX or SPDX SBOM — or just a package.json — and get it back with every package graded, plus an OpenVEX record of what was assessed and what you set aside. Write your rule once — for example, nothing graded D or F anywhere in the tree — and Dendra tells your build whether it passes. Everything exports as a dated audit pack, with the evidence annotated against S2C2F, NIST SSDF and the EU Cyber Resilience Act, whose reporting duties begin on 11 September 2026.
What it covers today
npm, in depth. Other registries run on the same interface and follow: PyPI, Maven and Gradle, Go, NuGet, SwiftPM and CocoaPods, Cargo, vcpkg and Conan.
Who it’s for
Engineering and security leads who need to answer two questions: what are we built on, and what should we do about it.