OPEN SOURCE · APACHE 2.0 · JVM-FIRST

Catch malicious dependency updates the moment they ship.

Marshal scans your Maven and Gradle dependencies for behavioral signals of supply-chain attacks, maintainer takeovers, signature drops, and suspicious version jumps, and blocks risky updates at PR time, before they reach your build.

Behavioral security for your dependencies.

View on GitHub → GitHub Action →

Get notified when the hosted watcher ships

Get notified when the hosted watcher ships. No marketing, no sharing, unsubscribe in one click.

CVE scanners catch yesterday's vulnerabilities. They wait for a public disclosure that arrives weeks or months after the malicious version is already in production. Marshal watches behavioral signals, what changed in this release, who pushed it, whether the signing key changed, and flags risky updates the same day they appear in the registry.

Real-time, not retrospective.

Marshal flags suspicious package versions within minutes of publication, not weeks after a CVE is filed.

Blocks at PR time, not after deploy.

The GitHub Action gates every dependency update with a 0 to 100 risk score and a clear reason. Slack webhook alerts included.

Complements CVE scanners.

Marshal catches what CVE databases miss: behavioral anomalies before disclosure. Run it alongside your existing scanner, not instead of it.

01

WATCH

Marshal reads your pom.xml or build.gradle and monitors Maven Central for new versions of every dependency in your project.

02

ANALYZE

Each update is scored 0 to 100 across 7 behavioral rules: maintainer changes, signature drops, dependency surface growth, repository changes, and version jumps.

03

BLOCK

Risky updates fail your PR check with a clear reason. Safe updates pass silently. Slack webhook alerts on critical findings.

I'm Usman, building Marshal solo from Tilburg. I've spent the last decade writing Java for teams where "dependency security" meant a periodic CVE scan and a hope that nothing landed between sweeps. Marshal is the tool I wished existed.

The CLI and GitHub Action are open-source under Apache 2.0 and available now at github.com/marshal-hq/marshal. The hosted watcher is how I keep the lights on. I post progress regularly.

-- Usman

GitHub X / Twitter Product Hunt Bluesky

The CLI and Action are open-source.

The CLI and GitHub Action are open-source under Apache 2.0. Install them today, self-host them, contribute to them. A Team tier with the hosted watcher and an Enterprise self-hosted tier are coming. No price is set yet.

Install the CLI →

Follow progress.

Get notified when the hosted watcher ships. Occasional notes in between. You can leave any time.

Get notified when the hosted watcher ships. No marketing, no sharing, unsubscribe in one click.

By submitting, you agree to receive updates from Marshal. We use MailerLite (EU) to send emails. See our Privacy Policy.