One publisher, listed channels.
A security tool is a target for impersonation, so this page is the canonical list of where Skarn is really published and by whom. If a package, account, or download claims to be Skarn and is not listed here, it is not ours. The list is mutual by construction: each channel below links back to getskarn.com, and this page under the domain names each channel.
Last updated 2026-08-18.
Official distribution channels
| Channel | Identity | How to check |
|---|---|---|
| Website and documentation | getskarn.com | You are on it. The GitHub org profile below names this domain as its website. |
| GitHub | github.com/skarn-security | Hosts the release binaries, the Homebrew tap, and the agent integration configs. The org profile links to getskarn.com and its membership is public. |
| Homebrew | skarn-security/tap |
Install with the fully-qualified name: brew install skarn-security/tap/skarn. The formula pins each release asset by sha256. |
| npm | @skarn-security scope | The launcher @skarn-security/skarn plus its per-platform binary packages. Published via npm trusted publishing from the skarn-security org; binaries are pinned by integrity hash. |
| Containers | ghcr.io/skarn-security/skarn |
Cosign-signed (Sigstore keyless), ships an SPDX SBOM and SLSA build provenance. |
| Snap Store | Publisher msrdjan |
The skarn snap is in store review and not yet published. Once live, this row will link the listing. |
The EULA at getskarn.com/terms/ states the official-channel rule in binding form. macOS binaries are Developer ID signed and Apple-notarized; the verify it yourself page carries the signature and checksum commands for every artifact type.
The publisher
Skarn is published first-party by its founder and developer, Srđan Marković (msrdjan on GitHub, npm, and the Snap Store; a public member of the skarn-security org). The licensor of record is named in the EULA, together with the planned assignment to a dedicated Estonian company. There are no other publisher accounts.
Report an impostor
Found a package, snap, extension, account, or domain presenting itself as Skarn that this page does not list? Treat it as unofficial and tell us at [email protected], the same address as in our security.txt. We respond to impersonation reports with the same priority as vulnerability reports.