Signal. Not noise.
Instead of you selecting tools, 0Day reads your organization’s dependency graph (all repos, every transitive dependency) and only alerts on threats that hit a package and version you actually use. Your scanner audits on its own schedule. 0Day tells you the moment something you ship comes under active attack.
How does 0Day catch a threat before the CVE?
AI triages and corroborates every signal across 20+ sources, and each one climbs a three-stage confidence pipeline before it reaches your team.
Seen once. A single source flags a package as potentially compromised.
A trusted or corroborated source confirms the signal, and we push it the moment it crosses that bar, often hours or days before it lands in an official advisory or gets a CVE.
WHY IT MATTERSThat head start is the whole point: time to pin a version, open a PR, or pause a deploy before an exploit reaches your repos, not after the patch notes catch up.
Multiple authoritative sources agree. The threat is verified and prioritized.
In practice, it works like this: 0Day continuously ingests raw signals from more than twenty threat intelligence sources: security-research firms, package-registry monitors, government feeds, and advisory databases. When a single source flags a package as potentially compromised, the signal enters the pipeline as a Candidate. When a trusted source or a second independent source corroborates it, the signal is promoted to Early Warning and pushed immediately to every organization whose repositories ship an affected version, typically hours or days before an official advisory is published or a CVE identifier is assigned. When multiple authoritative sources agree, the alert is marked Confirmed. That early-warning head start is the time a team needs to pin a version, open a fix PR, or pause a deploy before an exploit lands.
Two attacks. Two different ways in.
Real incidents, not hypotheticals. Each spread differently, so each diagram below is shaped like the attack it shows.
The “Shai-Hulud” worm
A self-propagating worm compromised maintainer npm tokens and republished trojanized versions of widely-used packages, stealing credentials from each infected machine and using them to infect the next maintainer’s packages in turn.
The xz-utils backdoor
A years-long social-engineering campaign earned commit access to xz/liblzma and slipped in a backdoor that would have compromised SSH on infected systems. It was caught only when an engineer noticed an unexplained performance regression before it reached stable distro releases.
See the full Incident Watch: every confirmed npm supply chain attack →
Push notifications that actually matter to your team.
Connect your GitHub org
A read-only, SBOM-based install at the organization level. We read dependency graphs, never your source code.
Push, not doom-scrolling
Stop scrolling security blogs, watching X, and skimming RSS feeds for threats that don’t touch your code. The moment one hits a repo your engineer owns, an iOS push lands. Nothing else to check.
Admin dashboard
Org-wide coverage, members, repositories, and alerts, all in one place, for the people who run security.
Privacy-first, by default.
Built for how engineers actually work.
Pick your stack once. See only the threats that matter. Act on what’s confirmed. Everything else gets filtered out before it reaches you. Tap a step or a side phone to bring it to the front.
Common questions.
Does 0Day replace our dependency scanner?
No. It sits in front of it. Scanners audit your dependencies and open patch PRs on their own cadence. 0Day is the awareness layer: it pushes an alert the moment a package and version you actually ship is flagged as under attack, often hours or days before an official advisory or CVE exists. Full comparison →
We don’t have a security team. Is 0Day for us?
Yes. 0Day was built for engineering teams without dedicated security staff. Connect your GitHub organization once and every engineer gets push alerts for the repos they own: no triage queue, no dashboard babysitting, no security hire required.
What access does the GitHub App need?
Read-only access to dependency manifests and the dependency graph, never the contents of your source files. Uninstall the app from GitHub and all access ends immediately. Security & Access details →
How is this different from advisory feeds and newsletters?
Feeds report everything; 0Day matches every threat against your organization’s dependency graph (all repos, every transitive dependency) and only alerts when a package and version you actually use is affected. Signal, not noise.
Built by an engineer, for engineers.
0Day is built and operated by Richard Lous, an independent software engineer based in the Netherlands. It started with a frustration: for months he watched major vulnerabilities surface across half a dozen channels (RSS feeds, X, LinkedIn, vendor blogs, advisory databases, scattered messages from peers). By the time a critical CVE in something he depended on hit his radar, hours (sometimes a full workday) had already passed. Every one of those channels was reactive: you have to be there, scrolling, when it lands. So he built the tool he wanted instead: alerts pushed to your phone, fast, corroborated across 20+ sources, and filtered by what you actually use. The iOS app is live on the App Store, rated 5.0; the organization product extends the same engine to your GitHub org’s full dependency graph, and the waitlist is open.