Vigilance vs SafeDep

Updated 5 Oct 2026

SafeDep blocks a package at install time when its threat feed lists the package as malicious. Vigilance finds the update that gained a hidden power, before you install it.

Start Free See Pricing

The Catch SafeDep Cannot Make

SafeDep checks each install against a feed of known malicious packages. Vigilance keeps no feed. It compares the version you trust with the version you install. It reports any file that can suddenly do more.

This page compares the two tools for buyers who want to stop a bad package before it runs. It uses SafeDep's own site, its GitHub pages and its pricing page. Read the wider market on our software supply chain security tools page, or see every comparison in the Compare hub.

A real one: axios, March 2026

axios is one of the most-installed packages on the internet. In release 1.14.1, its package.json gained a hidden install step. That step pulls down a remote-control program. One command sees it:

vigi diff --old ./axios-1.14.0 --new ./axios-1.14.1

HEADS UP. 1 file changed. package.json can now run a hidden helper on install and reach the network.

Read the full record on the axios attack page. The xz Utils backdoor shows the same pattern in a signed Linux release. Browse more cases in the attack library.

What SafeDep Does Well

SafeDep blocks malicious packages at the moment a developer installs them. Its open source tool PMG wraps the package manager and checks every install before any code runs. PMG covers npm, pnpm, yarn and bun for Node.js. It also covers pip, pipx, poetry and uv for Python. A developer does not need to change a habit.

PMG uses three layers. The first layer checks the package against SafeDep's malware database. The second layer is a dependency cooldown. It blocks recently published versions for a set window, so a new compromised release has time to be found. The third layer is an optional sandbox. It uses macOS Seatbelt or Linux Landlock, with Bubblewrap as a fallback, to limit what an install can touch.

The cooldown is a strong idea. Most supply chain attacks are found within hours or days of release. A team that waits a few days before it takes a new version avoids many of them. SafeDep builds that wait into the tool.

SafeDep also ships vet, an open source command line tool for dependency scanning. Vet reads npm, PyPI, Maven, Go, Ruby, Rust and PHP packages. It also reads container images and SBOM files in CycloneDX and SPDX formats. Its policies use CEL expressions. A team can write rules for licenses, vulnerability limits and scorecard needs. SafeDep says vet analyzes how your code uses a dependency, to rank real risks above CVE noise.

The cost of entry is low. PMG and vet use the Apache-2.0 license. PMG needs no account or API key. SafeDep also lists an MCP server for AI coding agents, an Agent API, and an inventory of AI agents and SDKs. Its platform claims SOC 2 Type II and ISO 27001:2013 certification. Those items matter to a buyer with a security questionnaire to answer.

SafeDep reaches many ecosystems. Its site lists npm, PyPI, Go, Maven, RubyGems, Cargo, NuGet and Docker registries. It also connects to GitHub, GitLab, Cursor, Claude and Windsurf.

Where It Falls Short

SafeDep falls short where a threat feed always falls short, which is on an attack that nobody has listed yet. Its protection depends on a verdict from SafeDep Cloud. A package that the feed has not seen has no verdict to apply.

SafeDep does cover that gap in part. The cooldown delays new versions, and the sandbox limits damage. Both have a cost. A cooldown also delays a legitimate security patch. A sandbox limits an install step, but it does not tell you what a new file in the package can do once your own program loads it.

The second limit is the network. PMG checks packages against SafeDep's community API. SafeDep says the tool needs no account. The PMG page also says the threat intelligence layer needs internet access for the best protection. SafeDep does not document an offline mode. A disconnected or air-gapped site cannot rely on it. Vigilance Pro opens no connection at all.

The third limit is the stage where SafeDep acts. PMG and vet act at install time and in pull requests and builds. A program that arrives some other way does not pass through a wrapped package manager. Examples are an installer, a signed desktop app, a container image or a Linux package archive. Vigilance reads inside deb, rpm, npm, pip, containers, MSI and ISO files. It works on those formats from one binary.

The fourth limit is scope. SafeDep focuses on open source packages and on AI coding agents. It does not claim to compare a trusted version of a vendor program with its update. The xz Utils backdoor and similar cases shipped in a release archive. Vigilance targets that shape of attack.

Some of these limits depend on your setup. A team that only installs npm and PyPI packages on laptops with a network will meet fewer of them.

Feature Comparison

The two tools overlap less than their names suggest. SafeDep decides from a feed, a cooldown and a sandbox. Vigilance decides from the files themselves. The table lists each difference that we can source.

Question SafeDep Vigilance
Blocks a listed malicious package at install Yes, with PMG No. It never blocks a program
Needs a threat feed to decide Yes, SafeDep Cloud No feed behind it
Delays brand-new package versions Yes, a configurable cooldown No
Sandboxes the install step Optional, on macOS and Linux No
Scans dependencies for known vulnerabilities Yes, with vet No
Writes policy rules in code Yes, CEL expressions No
Spots a file that gained the power to reach the network Not documented Yes
Compares the trusted version with the new one Not documented Yes
Reads inside deb, rpm, containers, MSI and ISO files Containers and SBOM files in vet Yes
Runs with no internet Not documented Yes, on Pro
Open source license Apache-2.0 for PMG and vet Closed source, free plan available
Hosted platform with SSO and RBAC Yes, on Enterprise No console. Fleet page from signed receipts

A cell that says "Not documented" means we found no statement on the SafeDep pages we read. It does not say the feature is missing.

When SafeDep Is the Better Fit

SafeDep is the better fit when your main risk is a developer or an AI agent that installs a package from npm or PyPI. PMG sits in the install path and stops a listed package before it runs. Vigilance does not block an install.

Choose SafeDep in these cases.

Choose Vigilance when the risk sits in the update itself. This covers a vendor installer, a signed app, a container image, a Linux archive or a build output. It also covers a site with no internet. Vigilance shows one file and one new capability. A normal update stays quiet.

Many teams will want both. SafeDep stands at the door of the package manager. Vigilance reads what came through. The two checks use different evidence, so one does not replace the other.

Pricing

SafeDep has a free plan, a Team plan at $100 per month for 5 endpoints, and a custom Enterprise plan. Its open source tools cost nothing. We took these numbers from the SafeDep pricing page.

The Free plan costs $0 and covers up to 3 SDLC endpoints. It includes real-time malicious package protection, 7 days of findings history and community support. It allows 10 package scans and 25 repository scans per endpoint per month.

The Team plan costs $100 per month per 5 endpoints, which is $20 per endpoint. It adds 90 days of findings history, an audit trail and email support. SafeDep lists an annual option with a 20% discount. It also offers a 30-day trial with no credit card, and the trial converts to the Free plan. The Enterprise plan adds SSO, RBAC, MDM rollout, SIEM and EDR integrations, and dedicated support. Its price depends on volume. A separate Threat Intel subscription covers the malicious package feed and API access.

SafeDep counts an endpoint as one point where third-party code enters. That can be a developer machine running PMG, a CI pipeline, a repository with pull request scanning, or an AI coding agent. The price grows with the number of those points.

Vigilance prices by company size and never by machine count. The Free plan costs $0 and runs forever on up to 50 machines. It needs a network and it sends telemetry. Pro starts at $999 per month or $9,990 per year, in Canadian dollars, flat for the whole company. Pro works offline and has no phone home. See Vigilance pricing for every band.

The models differ. SafeDep scales with endpoints. Vigilance steps on company size. A small team with few endpoints can stay free on both tools.

Which One Do You Need?

You need SafeDep if you want to stop known bad packages at install time, and Vigilance if you want to see new capability in any update. Many teams need both.

SafeDep answers the question, "Does a feed list this package as malicious?" Vigilance answers a different question. It asks, "Can this file do something the last version cannot do?" The first question works well on common npm and PyPI attacks. The second works on attacks with no listing, and on software that does not arrive through a package manager.

Known Risk versus New Risk

Known risk

A bug or a bad package someone already reported, with a name and a number. Most tools work here.

New risk

A file that gained a capability it never had, that no report covers yet. Vigilance works here.

Common Questions

Is Vigilance a SafeDep alternative?

Yes, for one job. Vigilance shows the file that gained a new capability, on your own machine, with no feed behind it. SafeDep blocks packages that its threat feed lists as malicious. Many teams can run both.

What does Vigilance do that SafeDep does not?

Vigilance compares the version you trust with the new one and reports any file that gained a capability, such as network access. It needs no threat feed. The Pro build has no network code at all, so it runs fully offline.

What does SafeDep do that Vigilance does not?

SafeDep blocks a package at install time with its PMG tool, checks packages against a live malware feed, and scans dependencies for known vulnerabilities with vet. It also offers a hosted platform with SSO and RBAC. Vigilance never blocks a program.

Is SafeDep free?

Yes, in part. The open source tools PMG and vet use the Apache-2.0 license. The hosted Free plan covers up to 3 SDLC endpoints. The Team plan costs $100 per month for 5 endpoints, and the Enterprise plan has custom pricing.

Does SafeDep work offline?

SafeDep does not document an offline mode. PMG checks packages against SafeDep's community API, so it needs internet access for its threat intelligence layer. Vigilance Pro opens no network connection at all.

Can SafeDep catch an attack that is not in its feed yet?

SafeDep describes two other layers. A dependency cooldown blocks recently published versions, and an optional sandbox limits what an install can reach. Vigilance takes a third route. It reads the new files and reports a new capability, with no feed.

Does Vigilance need the internet or a cloud account?

The Free plan runs online. Pro runs fully offline, with no cloud account.

Try It on Your Own Software.

Show it the version you run today and the one you are about to install. Download Vigilance and run it in one command.

Start Free Talk to Us

Talk to Us

A question, a pilot, or a bigger fleet? Send a note. It reaches a person.