Launched this week
Refuse
Block vulnerable package installs for you and your AI
61 followers
Block vulnerable package installs for you and your AI
61 followers
Refuse sits in front of npm, pip, cargo, gem, go + 13 more package managers and refuses known-vulnerable installs before they hit disk โ the moment you (or your coding agent) run them. Also, Open-source, self-hostable, one Docker container.





Refuse
Nice launch. The no agent override bit is the right instinct.
Iโd want a small receipt when something is blocked or a human overrides it: package, version, CVE/source, who approved, and what changed next. Are overrides repo policy, or an explicit approval event?