Security
Findings Hammerhead reports in the Security class, kept separate from Hygiene and Info findings.
Audit potentially untrusted software repositories on your own machine.
Hammerhead is a defensive security tool from Talarurus: a local-first command-line tool written in Go. Hammerhead is built around a security-focused SafeWalker architecture.
Approach
Hammerhead is made for the moment before you trust a repository: when you have the code but have not yet decided to depend on it.
Use the Hammerhead CLI on your own machine, against a repository you want to examine.
Hammerhead audits the potentially untrusted repository. Hammerhead is built around a security-focused SafeWalker architecture.
Each finding is reported as Security, Hygiene, or Info.
Review results in the terminal, or take the JSON output into your own tools.
Architecture
Hammerhead is built around a security-focused SafeWalker architecture.
Hammerhead is defensive security tooling for auditing potentially untrusted software repositories. It is local-first, written in Go, and reports Security, Hygiene, and Info findings in the terminal or as JSON.
Findings
Hammerhead separates its findings into three classes. Each class is reported separately from the other two.
Findings Hammerhead reports in the Security class, kept separate from Hygiene and Info findings.
Findings Hammerhead reports in the Hygiene class, kept separate from Security and Info findings.
Findings Hammerhead reports in the Info class, kept separate from Security and Hygiene findings.
Reports
The same findings, in the format that suits the job.
A human-readable report for reviewing results directly in your shell.
Machine-readable output for scripts, pipelines, and other tools.
Model
Hammerhead is local-first. Audits run on your own machine, where the repository already is.
Hammerhead is written in Go and used from the command line, so it fits manual review and scripted workflows alike.
Follow Talarurus on GitHub for project updates. Found a vulnerability in Hammerhead? Report it privately.