Skip to content
Published

Last reviewed: 2026-07-25

Package Finder

Search and evaluate packages across major ecosystems before adoption using organization policies and a token with package-finder read scope.

Evaluate a package before adoption

Package Finder lets teams search and evaluate packages before adding them to a repository. It supports npm, pip, Maven, Cargo, Composer, Gem, and Go (gomod) packages, then applies your organization’s policies to the candidate.

Use the smallest access needed

For API or MCP use, the service token must include the package-finder:read scope. Search for the exact package and ecosystem, then evaluate the version you plan to adopt. Results belong to the selected organization and reflect that organization’s policies; do not use a token from another client or organization.

Make a reviewable decision

Treat an evaluation as input to a technical decision. Review policy outcomes, package version, and ecosystem together. The category shown is the organization-effective one (org override if set, otherwise the global catalog category), aligned with Dependency Advisor policy evaluation. A package with the same name in another ecosystem is not the same dependency. Re-evaluate after a policy change or when adopting a new version.

Related documentation