Trust

One publisher, listed channels.

A security tool is a target for impersonation, so this page is the canonical list of where Skarn is really published and by whom. If a package, account, or download claims to be Skarn and is not listed here, it is not ours. The list is mutual by construction: each channel below links back to getskarn.com, and this page under the domain names each channel.

Last updated 2026-08-18.

Official distribution channels

ChannelIdentityHow to check
Website and documentation getskarn.com You are on it. The GitHub org profile below names this domain as its website.
GitHub github.com/skarn-security Hosts the release binaries, the Homebrew tap, and the agent integration configs. The org profile links to getskarn.com and its membership is public.
Homebrew skarn-security/tap Install with the fully-qualified name: brew install skarn-security/tap/skarn. The formula pins each release asset by sha256.
npm @skarn-security scope The launcher @skarn-security/skarn plus its per-platform binary packages. Published via npm trusted publishing from the skarn-security org; binaries are pinned by integrity hash.
Containers ghcr.io/skarn-security/skarn Cosign-signed (Sigstore keyless), ships an SPDX SBOM and SLSA build provenance.
Snap Store Publisher msrdjan The skarn snap is in store review and not yet published. Once live, this row will link the listing.

The EULA at getskarn.com/terms/ states the official-channel rule in binding form. macOS binaries are Developer ID signed and Apple-notarized; the verify it yourself page carries the signature and checksum commands for every artifact type.

The publisher

Skarn is published first-party by its founder and developer, Srđan Marković (msrdjan on GitHub, npm, and the Snap Store; a public member of the skarn-security org). The licensor of record is named in the EULA, together with the planned assignment to a dedicated Estonian company. There are no other publisher accounts.

Report an impostor

Found a package, snap, extension, account, or domain presenting itself as Skarn that this page does not list? Treat it as unofficial and tell us at [email protected], the same address as in our security.txt. We respond to impersonation reports with the same priority as vulnerability reports.