Can you get in touch with the guys at OWASP Dependency Check? It's one of their more mature projects, and it essentially does a lot of what you described and then some, including for Python projects.<p><a href="https://www.owasp.org/index.php/OWASP_Dependency_Check" rel="nofollow">https://www.owasp.org/index.php/OWASP_Dependency_Check</a><p>I can make a connection between you and Jeremy Long (head of the project) if you'd like. He's also on twitter as @ctxt