Safeguard Gold Open Source is a free directory of open source intelligence. Look up any package across more than twenty ecosystems and see CVEs, CWEs, KEV, EPSS, malware signals and SGZ zero-day advisories before you install it.
Developers make dependency decisions in seconds, usually with nothing in front of them but a download count. Safeguard Gold Open Source exists to put real evidence in that moment, and it is free. It is a public directory covering packages across more than twenty ecosystems, and for each one it shows known vulnerabilities with CVE and CWE identifiers, presence in the CISA Known Exploited Vulnerabilities catalog, EPSS exploit probability, malware and typosquat signals, and MITRE ATT&CK mappings.
The directory goes beyond packages. It also covers AI models, MCP servers and agent skills, which are now part of the same supply chain and are rarely checked with the same rigour as a library. Zero-day advisories discovered by Safeguard research are published here as SGZ identifiers, so a finding can reach you before a public CVE exists for it. Intelligence is refreshed continuously rather than published once, so a package that looked clean last month is re-evaluated as new advisories and malware signals arrive.
Access is designed to fit where the decision happens. There is a free read API, a Chrome extension that surfaces the same intelligence on package pages you already browse, and a free CI gate so a build can fail on a package the directory flags. Nothing about this tier requires a paid Safeguard subscription.
Gold Open Source is the free front door to the wider Safeguard platform. The Gold Registry adds hardened, zero-CVE, zero-malware, SLSA-signed drop-in artifacts for teams that want to start clean rather than patch later, and Safeguard ESSCM, OSM, TPRM, Portal and Compliance cover the full life cycle of the software supply chain with continuous scanning, software composition analysis, static and dynamic application security testing, reachability analysis and autonomous remediation. You can use the directory on its own for as long as you like.
Highlights
Free, and free to keep using. A public directory of open source intelligence across more than twenty ecosystems, with a read API, a Chrome extension and a CI gate, none of it behind a paid subscription.
The evidence a lockfile decision needs. CVEs and CWEs, CISA KEV membership, EPSS exploit probability, malware and typosquat signals and MITRE ATT&CK mappings for the package in front of you.
Covers the AI supply chain too. Models, MCP servers and agent skills sit in the same directory as packages, with SGZ zero-day advisories from Safeguard research published as they are found.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
This listing has one pricing dimension: Free. You pay nothing to use it. There are no tiers, quantities, or usage add-ons to configure. The single Free dimension gives you access to the public package and CVE lookup directory. This directory offers verified components with vulnerability coverage across many ecosystems, plus a read-only lookup interface. Because only one dimension exists, there is no scaling logic or upgrade path within this Marketplace offering. Your billing stays at zero regardless of how you use the directory.
Top-of-mind questions for buyers
What do I get access to under the Free dimension on this listing?
You get the public Gold Open Source directory. It lists verified components across 20-plus ecosystems, with CVE and known-exploited vulnerability coverage. You also get a read-only lookup interface, a JSON API for lookups, README security badges, and a CI gate action. No login is required to browse the directory.
Does the Free directory let me pull or download the verified packages, or only look them up?
The Free directory is a lookup and read-only interface. You can search components, view CVE and vulnerability data, and read attestations. Pulling hardened artifacts at volume, private forks, or dedicated mirrors are separate capabilities not part of this Free lookup dimension. The directory and its read API stay free.
Will my cost ever change as I use the directory more heavily?
No. This listing has one Free dimension and no metered usage, tiers, or included-amount cutoffs. Your billing stays at zero no matter how many lookups you run. There is no automatic upgrade or overage charge within this Marketplace offering. Nothing in your usage triggers a cost change.
gold.safeguard.sh+1
Helpful?
Vendor refund policy
Safeguard Gold Open Source is free. There is no charge for the directory, the read API, the Chrome extension or the CI gate, so there is nothing to refund. If you later purchase a paid Safeguard product, that product carries our metered refund policy: we charge only what was consumed and refund the remaining balance. Questions about billing or cancellation go to hi@safeguard.sh with your AWS account ID and the product name. We respond within one business day.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Safeguard support is available to every AWS Marketplace customer.
Email: hi@safeguard.sh
Contact form: https://safeguard.sh/company/contact
Documentation: https://docs.safeguard.sh
Directory: https://gold.safeguard.sh
Level of support you can expect
Our team responds Monday to Friday and targets a first response within one business day for all enquiries, including onboarding, read API access and CI gate setup. Severity one issues affecting the directory or the API are triaged as soon as they are received. Customers who later move to a paid Safeguard product can add named technical contacts, a shared channel, onboarding assistance and an agreed response schedule.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Safeguard Portal is the SBOM command center. Publish, version, diff and securely share software bills of materials with customers and auditors, with EO 14028 verification and full audit trails.
Snyk is a developer security platform that finds and fixes vulnerabilities across code, open source, containers, and AI generated software from first line of code to production.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.