# Identify and Replace Low-Reputation Third-Party Packages

Evaluate third-party packages in your code based on a wide range of open-source reputation characteristics. Replace existing low-reputation packages and avoid new ones to reduce security and operational risk in your production environment.

## Give Your Developers Security Superpowers

Replace Low-Reputation Dependencies to Strengthen Your Supply Chain

Help your developers maintain high quality dependencies by identifying and alerting on low-reputation third party packages in real-time on code push, on a pull request, or asynchronously.

Deliver Rich Third-Party Reputation Context

Arm your developers with rich package context such as count of releases, days since last publish, number of recent downloads, number of dependent packages, OpenSSF score, number of GitHub stars, and more.

Empower Developers to Fix Risks in Real-Time

Build easy, developer-native interactions to encourage upgrades to low-reputation third-party software packages while keeping developers in their existing tools and workflows.

## Uplevel Your Code Security with Third-Party Package Reputation

### Package Reputation Analysis

Give your developers all the context they need to avoid using low-reputation third-party packages.

- [Identify low-reputation characteristics](/content/use-cases/package-reputation#w-tabs-0-data-w-pane-0/index.html)  
Provide visibility into count of releases, last published date, downloads count, dependent packages, number of GitHub stars, and more for every package.
  
- [Notify developers directly](/content/use-cases/package-reputation#w-tabs-0-data-w-pane-1/index.html)  
Notify developers about newly introduced third-party packages with low reputation characteristics.
  
- [Monitor existing packages](/content/use-cases/package-reputation#w-tabs-0-data-w-pane-2/index.html)  
Alert on existing packages that become low-reputation based on lack of updates.
  
- [Use third-party validation](/content/use-cases/package-reputation#w-tabs-0-data-w-pane-3/index.html)  
Provide developers with third-party reputation context such as OpenSSF Scorecard.

### Real-Time Developer Workflows

Identify and communicate with developers in real-time on detected low-reputation packages so they can adjust before their code is in production.

- [Communicate early](/content/use-cases/package-reputation#w-tabs-1-data-w-pane-0/index.html)  
Let developers know before their code containing low-reputation packages is merged to production.
  
- [Collaborate in chat](/content/use-cases/package-reputation#w-tabs-1-data-w-pane-1/index.html)  
Integrate with Slack & Microsoft Teams to communicate with developers in tools they already use, without the need to opt-in.
  
- [Facilitated peer code reviews](/content/use-cases/package-reputation#w-tabs-1-data-w-pane-2/index.html)  
Empower developers to kickoff peer review workflows directly from chat alerts on a low-reputation package.
  
- [Automated ticket management](/content/use-cases/package-reputation#w-tabs-1-data-w-pane-3/index.html)  
Arnica’s Jira integration auto-opens tickets when low-reputation packages are introduced and auto-closes when they’re mitigated.

### Avoid Low-Quality Packages

Go beyond Software Composition Analysis and leverage Arnica’s package reputation analysis to ensure that your developers are using reliable, high-quality third-party packages.

- [Maintain high-reputation packages](/content/use-cases/package-reputation#w-tabs-2-data-w-pane-0/index.html)  
Keep the potential risks of low-reputation packages out of your code, even if they don’t contain known security issues.
  
- [Rich severity insights](/content/use-cases/package-reputation#w-tabs-2-data-w-pane-1/index.html)  
Prevent low-reputation packages from entering your source code based on rich severity scoring across CVSS, EPSS, and KEV.
  
- [Reduce operational risk](/content/use-cases/package-reputation#w-tabs-2-data-w-pane-2/index.html)  
Reduce the operational risks and tech debt that come with low-reputation package usage.

## Customer testimonials

Hear what Arnica users have to say about how pipelineless security helped them build their own world-class application security program.

Arnica has been a piece of allowing us to accelerate like that. As I've taken my team and split it up into smaller groups - some two-person teams tackling fairly big functionality - Arnica being part of it has been really successful for us.

.png)

Brad Young  
VP of Technology  
[View Case Study](/content/case-studies/its-case-study/index.html)

Arnica helps us reduce noise by providing metrics on the likelihood of exploitation and reprioritizing critical severity vulnerabilities based on Arnica’s logic, exposing the most important risks to deal with immediately. We set all of this up in the first month.

Jordan Bailey  
Principal AppSec Engineer  
[View Case Study](/content/case-studies/n-able/index.html)

For risks outputs from Static Application Security Testing (SAST) or Software Composition Analysis (SCA), we’ve been able to reduce mean-time-to-awareness of the risk for the developer as well as mean-time-to-remediation.

Mark Stanislav  
VP of Security Engineering & GRC  
[View Case Study](/content/case-studies/fullstory/index.html)

## Go beyond code security with package reputation analysis.

Keep low-reputation packages out of your code with Arnica's package reputation management.
