Thirdpass

Coordinated software security review

Thirdpass coordinates security reviews of software. It makes review evidence versioned, reusable, and practical to scale.

$ thirdpass review-any

Campaigns

Campaigns group review work around software and ecosystems people care about. The default campaign is the broad open-source review pool; focused campaigns make specific missions visible.

All campaigns

How Thirdpass Works

Thirdpass separates artifact handling from review coordination. That lets the same review engine support package release coverage today and broader software security campaigns over time.

Extensions resolve artifacts
Ecosystem extensions find dependency files, understand registry metadata, and fetch package archives by exact version.
Campaigns assign work
The server keeps campaign-specific queues. The default campaign is the broad open-source review pool.
The CLI reviews focused scope
Each review focuses on selected files or changes, while the rest of the source remains available as context.
Evidence becomes reusable
Submitted reviews record exactly what was checked so campaigns, projects, and future reviews can build on the evidence.
Read the docs

Designed for multiple ecosystems

Thirdpass supports dependency ecosystems through extensions.

EcosystemRegistryExtensionAvailability
Rustcrates.iothirdpass-rsBuilt in
Pythonpypi.orgthirdpass-pyBuilt in
JavaScriptnpmjs.comthirdpass-jsBuilt in
GitHubgithub.comthirdpass-githubBuilt in
Ansible Galaxygalaxy.ansible.comthirdpass-ansibleExternal