Catches the supply-chain attacks that have no CVE — typosquatting, dependency confusion, install-time malware, and lockfile tampering — across npm, PyPI, Go, and Cargo, fully offline.
Stowaway is an offline software supply-chain integrity scanner. It catches the attacks that have no CVE: attackers publish typosquats one keystroke from famous names and wait for a mistyped install; they exploit dependency confusion by registering your internal package names on public registries so resolvers fetch their code instead of yours; and they hide install-hook malware — code that runs the moment a package is installed, before you ever import it — behind obfuscation and tampered lockfiles. Stowaway detects all four, across npm, PyPI, Go, and Cargo. Publicly released as v0.1.0 (Aug 2026): PyPI-packaged (src-layout), documented with a MkDocs site, CodeQL-hardened in CI, and citable via CITATION.cff.
Stowaway is fully offline (zero network I/O at scan time), fully static (scanned code is never executed), and deterministic (same input → byte-identical output). A single pass walks the tree with size caps and .gitignore awareness, hands each ecosystem's manifests/lockfiles/install-hooks to its parser, runs all five rule families over the resulting ScanContext, folds findings into per-package priorities via a transparent risk model, and emits JSON, self-contained HTML, and SARIF 2.1.0 with a --fail-on CI merge gate. It complements CVE/SCA scanners rather than replacing them.
Python 3.11+, Standard library only (0 runtime deps), Damerau-Levenshtein, SARIF 2.1.0, Self-contained HTML, npm / PyPI / Go / Cargo parsers, Offline / deterministic