Watch what you depend on

Forge re-scans every listing on a schedule and diffs each scan against the last one: a new npm maintainer, a new postinstall script, obfuscated code that was not there before, a tool surface that grew a privileged capability, a fresh CVE, a revoked publisher. Watch a package and you get told when one of those lands — in this feed, or as a signed webhook.