Pqurp – Quarantine Window for Packages to Prevent Supply Chain Attacks
Speculative protocol for package quarantine without a reference implementation or registry buy-in.

Maps hidden monopolies like Soitec wafers and Ajinomoto dielectric films.
Semiconductor investors and hardware supply chain analysts
Investmap · Supply Chain Dive · Semiconductor Industry Association reports
Speculative protocol for package quarantine without a reference implementation or registry buy-in.
NPM supply chain scanner competing against Socket, Snyk, and npm audit.
Yet another package proxy when Sonatype, Verdaccio, and Cloudsmith already own this space.
Dependabot already does this without the AI agent overhead.
Behavioral malware scanning before install, unlike pip-audit.
From Witness/in-toto creators, keyless attestation blocks poisoned CI runs.