Trust

One publisher, listed channels.

A security tool is a target for impersonation, so this page is the canonical list of where Skarn is really published and by whom. If a package, account, or download claims to be Skarn and is not listed here, it is not ours. The list is mutual by construction: each channel below links back to getskarn.com, and this page under the domain names each channel.

Last updated 2026-09-18.

Official distribution channels

ChannelIdentityHow to check
Website and documentation getskarn.com You are on it. The GitHub org profile below names this domain as its website.
GitHub github.com/skarn-security Hosts the release binaries, the Homebrew tap, and the agent integration configs. The org profile links to getskarn.com and its membership is public.
Homebrew skarn-security/tap Install with the fully-qualified name: brew install skarn-security/tap/skarn. The formula pins each release asset by sha256.
npm @skarn-security scope The launcher @skarn-security/skarn plus its per-platform binary packages. Published via npm trusted publishing from the skarn-security org; binaries are pinned by integrity hash.
Containers ghcr.io/skarn-security/skarn Cosign-signed (Sigstore keyless), ships an SPDX SBOM and SLSA build provenance.

The EULA at getskarn.com/terms/ states the official-channel rule. The verify it yourself page carries the verification commands for every artifact type.

The publisher

Publisher: Skarn Software OÜ.

Report an impostor

Found a package, snap, extension, account, or domain presenting itself as Skarn that this page does not list? Treat it as unofficial and tell us at [email protected], the same address as in our security.txt.