djinn VS packj

Compare djinn vs packj and see what are their differences.

djinn

Source code for the Djinn CI platform (by djinn-ci)

packj

Packj stops :zap: Solarwinds-, ESLint-, and PyTorch-like attacks by flagging malicious/vulnerable open-source dependencies ("weak links") in your software supply-chain (by ossillate-inc)
InfluxDB - Power Real-Time Data Analytics at Scale
Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.
www.influxdata.com
featured
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com
featured
djinn packj
20 38
39 614
- 3.3%
7.1 7.2
6 months ago 29 days ago
Go Python
Apache License 2.0 GNU Affero General Public License v3.0
The number of mentions indicates the total number of mentions that we've tracked plus the number of user suggested alternatives.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.

djinn

Posts with mentions or reviews of djinn. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2022-12-02.
  • Monthly 'Shameless Self Promotion' thread - 2022/12
    8 projects | /r/devops | 2 Dec 2022
    Djinn CI is a newly launched CI platform, with the following features:
  • Act: Run your GitHub Actions locally
    14 projects | news.ycombinator.com | 25 Nov 2022
    I've built a CI platform [1] that does support running your CI builds without the server using an offline runner. I wrote about it here before: https://blog.djinn-ci.com/showcase/2022/08/06/running-your-c...

    [1] - https://about.djinn-ci.com/

  • Djinn CI – open-source CI platform
    2 projects | news.ycombinator.com | 22 Nov 2022
    Author of Djinn CI here. This is a CI platform that I developed, it is open source but there is also a hosted offering https://about.djinn-ci.com. Some of the features are detailed below:

    * Fully virtualized Linux VMs

    * GitHub/GitLab integration

    * Variable masking

    * Configurable artifact cleanup limits

    * Multi-repository builds

    * Repeatable builds with cron jobs

    * Custom QCOW2 images for builds

    I've written some posts demonstrating the features of the platform which I have posted here before:

    * https://blog.djinn-ci.com/showcase/2022/08/06/running-your-c...

    * https://blog.djinn-ci.com/showcase/2022/08/16/using-multiple...

    For further reading there is also the documentation sub-site at https://docs.djinn-ci.com/.

    If you have any questions don't hesitate to reach out.

  • Blazing fast CI with MicroVMs
    3 projects | news.ycombinator.com | 18 Nov 2022
    Good article. Firecracker is something that has definitely piqued my interest when it comes to quickly spinning up a throwaway environment to use for either development or CI. I run a CI platform [1], which currently uses QEMU for the build environments (Docker is also supported but currently disabled on the hosted offering), startup times are ok, but having a boot time of 1-2s is definitely highly appealing. I will have to investigate Firecracker further to see if I could incorporate this into what I'm doing.

    Julia Evans has also written about Firecracker in the past too [2][3].

    [1] - https://about.djinn-ci.com

    [2] - https://jvns.ca/blog/2021/01/23/firecracker--start-a-vm-in-l...

    [3] - https://news.ycombinator.com/item?id=25883253

  • From WampServer, to Vagrant, to QEMU
    5 projects | dev.to | 8 Nov 2022
    At this point when it came to my hobbyist development, I had moved past PHP and started learning Go, and was looking to do some serious development with this for a CI platform I had an idea for. By now, I had a firmer grasp of the software stack I wanted to work with, a better understanding of how everything pieced together. And so I went about developing that CI platform, that would later become Djinn CI. I uninstalled VirtualBox and Vagrant and fully committed to using QEMU, booting up the local machine was as simple as hitting CTRL + R in my terminal, searching for qemu and hitting enter, an elegant solution I know.
  • Looking for a mature distributed task queuer/scheduler in go
    12 projects | /r/golang | 6 Oct 2022
    I use mcmathja/curlyq and found it pretty reliable. This is the queue I use for Djinn CI an open source CI platform I developed.
  • Using multiple repositories in your CI builds
    4 projects | dev.to | 16 Aug 2022
    Djinn CI makes working with multiple repositoriesin a build simple via the sourcesparameter in the build manifest. This allows you to specify multiple Git respositories to clone into your build environment. Each source would be a URL that could be cloned via git clone. With most CI platforms, a build's manifest is typically tied to the source code repository itself. With Djinn CI, whilst you can have a build manifest in a source code repository, the CI server itself doesn't really have an understanding of that repository. Instead, it simply looks at the sources in the manifest that is specified, and clones each of them into the build environment.
  • Running your CI builds without the server
    2 projects | dev.to | 6 Aug 2022
    Perhaps the one feature that sets Djinn CI out from other CI platforms is the fact that is has an offline runner. The offline runner allows for CI builds to be run without having to send them to the server. There are some limitations around this, of course, but it provides a useful mechanism for sanity checking build manifests, testing custom images, and for building software without the need for a CI server.
  • Show HN: OneDev – A Lightweight Gitlab Alternative
    4 projects | news.ycombinator.com | 2 Aug 2022
    You mention CI being done in a distributed fashion. Could you elaborate on what you mean by this?

    I'm asking as I'm someone who has developed a CI platform [1], and one of its features is the offline runner [2]. The offline runner allows you to run your CI builds on your own computer, and does not communicate with the CI server whatsoever. Is this what you had in mind?

    [1] https://about.djinn-ci.com

    [2] https://docs.djinn-ci.com/user/offline-runner/

  • Monthly 'Shameless Self Promotion' thread - 2022/06
    14 projects | /r/devops | 2 Jun 2022
    Djinn CI is a newly launched CI platform, with the following features:

packj

Posts with mentions or reviews of packj. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2023-11-14.
  • Rust Without Crates.io
    5 projects | news.ycombinator.com | 14 Nov 2023
    Creator of Packj [1] here. How do you envision sandboxing/security policies will be specified? Per-lib policies when you've hundreds of dependencies will become overwhelming. Having built an eBPF-based sandbox [2], I anticipate that accuracy will be another challenge here: too restrictive will block functionality, too permissive defeats the purpose.

    1. https://github.com/ossillate-inc/packj flags malicious/risky NPM/PyPI/RubyGems/Rust/Maven/PHP packages by carrying out static+dynamic+metadata analysis.

  • A Study of Malicious Code in PyPI Ecosystem
    4 projects | news.ycombinator.com | 8 Sep 2023
    Cool project. How do you feel about projects like OpenSSF scorecards or even the checks that socket.dev do today on these packages to help determine risk?

    https://github.com/ossillate-inc/packj/blob/main/.packj.yaml

    Secondly, what about impersonation where attackers imitate a popular package and its respective metadata?

  • How to use Podman inside of a container
    4 projects | news.ycombinator.com | 26 Apr 2023
    I built Packj [1] sandboxing for securing “pip/NPM install”. It uses strace for sandboxing and blocks access to sensitive files and limits traffic to known-good IP addresses.

    1. https://github.com/ossillate-inc/packj

  • NPM Provenance Public Beta
    5 projects | news.ycombinator.com | 19 Apr 2023
    Great work! This provenance check is going to be very valuable for enforcing supply-chain security. We are working on adding support to check for provenance in Packj.

    1. https://github.com/ossillate-inc/packj flags risky/malicious NPM/PyPI/Ruby dependencies

  • Show HN: TypeScript Security Scanner
    2 projects | news.ycombinator.com | 12 Apr 2023
    Cool project. Would love to integrate this in Packj [1] as one of the open-source SAST scanners. Will DM you.

    1. https://github.com/ossillate-inc/packj flags malicious/risky open-source dependencies.

  • Packj flags malicious/risky open-source packages
    1 project | news.ycombinator.com | 14 Feb 2023
  • Show HN: Coder Guard – Protect Your IDE from Malicious Extensions
    1 project | news.ycombinator.com | 26 Jan 2023
    Very cool! I've built something similar, but for packages: https://github.com/ossillate-inc/packj Would love to talk.
  • Ask HN: What Are You Working on This Year?
    49 projects | news.ycombinator.com | 2 Jan 2023
    Working on a marketplace (based on Packj [1]) to allow open-source developers to make money by selling "assured" software artifacts.

    1. Packj https://github.com/ossillate-inc/packj flags malicious and other "risky" open-source dependencies in your software supply chain.

  • Compromised PyTorch-nightly dependency chain December 30th, 2022
    3 projects | news.ycombinator.com | 31 Dec 2022
    I’ve created Packj sandbox [1] for “safe installation” of PyPI/NPM/Rubygems packages

    1. https://github.com/ossillate-inc/packj

    It DOES NOT require a VM/Container; uses strace. It shows you a preview of file system changes that installation will make and can also block arbitrary network communication during installation (uses an allow-list).

  • Vulnerability scanner written in Go that uses osv.dev data
    7 projects | news.ycombinator.com | 16 Dec 2022
    Great to see a developer-friendly tool around OSV! Packj [1] uses OSV APIs to report vulnerable PyPI/NPM/Rubygems packages. Disclaimer: I built it.

    1. https://github.com/ossillate-inc/packj flags malicious/risky packages.

What are some alternatives?

When comparing djinn and packj you can also consider the following projects:

gatus - ⛑ Automated developer-oriented status page

kubesploit - Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang, focused on containerized environments.

tracetest - 🔭 Tracetest - Build integration and end-to-end tests in minutes, instead of days, using OpenTelemetry and trace-based testing.

paperclips - Universal Paperclips mirror

atuin - ✨ Magical shell history

meta - Meta discussions and unicorns. Not necessarily in that order.

onedev - Git Server with CI/CD, Kanban, and Packages. Seamless integration. Unparalleled experience.

maloss - Towards Measuring Supply Chain Attacks on Package Managers for Interpreted Languages

ddosify - Effortless Kubernetes Monitoring and Performance Testing. Available on CLI, Self-Hosted, and Cloud

roqr - QR codes that will rock your world

goimports - [mirror] Go Tools

firejail - Linux namespaces and seccomp-bpf sandbox