Dustico provides a dynamic source-code analysis platform to prevent open-source software supply-chain attacks.
Its code sandbox detects malicious behavior in code changes (combining static and dynamic analysis), helping to prevent unwanted malicious code and open-source packages before the code is deployed to production.