Skip to main content

Enterprise security and monitoring for developers. Auto-restart, threat detection, pkl inspector, supply chain protection.

Project description

stillrunning

Version Protected by stillrunning Python License

Supply chain security for teams without security teams.

pip install stillrunning

What it does

  • AI Package Review — Claude Haiku scans every unknown pip/npm package at install time
  • Blocks malicious packages before they run — intercepts installs, checks against live threat feed
  • Tripwire Monitor — alerts when sensitive files (.env, SSH keys, private_key.pem) are accessed
  • File Integrity — SHA256 hash monitoring for critical files
  • Honeypot Credentials — fake .env files that alert when accessed
  • Learns your environment — auto-whitelists your processes, alerts on anomalies
  • Updates itself — syncs blocklist every 60 minutes from 8 threat intel sources

The attack it was built for

In 2026, North Korean state hackers published WAVESHAPER.V2 — 1,700+ malicious packages across npm and PyPI. Credential stealers disguised as logging utilities. Traditional AV found nothing. Enterprise tools cost $50k/year.

stillrunning catches it at install time, before it ever runs.

Live proof

stillrunning.io/threats — real-time intercept dashboard.

Not a demo. Every package check, every block, every threat advisory — live.

Quick start

# Install
pip install stillrunning

# Run setup wizard
stillrunning --setup

The setup wizard detects your running processes, configures monitoring, and connects to the live threat feed. Takes 3 minutes.

Troubleshooting

# Run 12 diagnostic checks
stillrunning --doctor

Checks: config validation, API connectivity, token validation, process monitor health, threat feed sync, disk space, and more.

With subscription token

For premium features (AI review, tripwire, file integrity):

# Install with token
curl -sSL https://stillrunning.io/install | python3 - --token YOUR_TOKEN

# Or add to stillrunning.yaml
token: "sr_your_token_here"

Get your token at stillrunning.io/pricing

Pricing

Tier Monthly Annual (save 20%) Features
Personal $9/mo $90/year Process monitor, auto-restart, Telegram alerts
Basic $29/mo $290/year + File integrity, tripwire, honeypot
AI $49/mo $490/year + AI package review (100 scans/day), central dashboard
Enterprise $499/mo Custom + Unlimited scans, SIEM, SSO, SOC2 compliance

Features by Tier

Personal ($9/mo)

  • Process monitoring with auto-restart
  • Telegram/Slack/Email alerts
  • Basic threat blocklist
  • 1 machine

Basic ($29/mo)

Everything in Personal, plus:

  • Tripwire Monitor — instant alerts when .env, SSH keys, or secrets are accessed
  • File Integrity — SHA256 tracking of critical files
  • Honeypot Credentials — canary files that catch malware
  • 3 machines

AI ($49/mo)

Everything in Basic, plus:

  • AI Package Review — Claude Haiku analyzes every unknown package
  • Verdicts: CLEAN / SUSPICIOUS / DANGEROUS
  • 100 AI scans per day
  • Central dashboard for all machines
  • Unlimited machines

Enterprise ($499/mo)

Everything in AI, plus:

  • Unlimited AI scans
  • SIEM integration (Splunk, Elastic, etc.)
  • SSO (SAML, OIDC)
  • SOC2 compliance reports
  • 4-hour SLA
  • Dedicated support

Stats

  • 56+ malicious packages in blocklist
  • 8 threat sources: CISA, OSV.dev, NVD, GitHub, npm, Snyk, Socket, Gemini AI
  • AI-powered discovery — Gemini 2.5 Flash hunts new threats in security blogs
  • Updated hourly

Badge

Show your project is protected:

![Protected by stillrunning](https://stillrunning.io/badge/protected)

Public API

Check if a package is safe before installing:

curl https://stillrunning.io/api/check-package/pip/requests
# Returns: {"package": "requests", "status": "CLEAN", ...}

curl https://stillrunning.io/api/check-package/pip/logutilkit
# Returns: {"package": "logutilkit", "status": "BLOCKED", "severity": "CRITICAL", ...}

Rate limit: 10 requests/hour (free), unlimited with subscription.

Referral Program

Earn 20% recurring commission on customers you refer.

  1. Get your code from stillrunning.io/dashboard
  2. Share: stillrunning.io/ref/YOUR_CODE
  3. Earn 20% of every payment

Links

License

MIT License

Patent Pending — US Provisional Application filed April 12, 2026

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

stillrunning-1.9.2.tar.gz (55.3 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

stillrunning-1.9.2-py3-none-any.whl (57.3 kB view details)

Uploaded Python 3

File details

Details for the file stillrunning-1.9.2.tar.gz.

File metadata

  • Download URL: stillrunning-1.9.2.tar.gz
  • Upload date:
  • Size: 55.3 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.3

File hashes

Hashes for stillrunning-1.9.2.tar.gz
Algorithm Hash digest
SHA256 6cf6a6a0bad93d47cb6b841fc0884ca22fd1d85e6eada5d94112350f69bbc915
MD5 eb271111df6dbf835a511e06abc0f4e8
BLAKE2b-256 edb4395c243ff0c3f30ad78d18dc113b34a6587d866a4d3ae7eeed2e163be671

See more details on using hashes here.

File details

Details for the file stillrunning-1.9.2-py3-none-any.whl.

File metadata

  • Download URL: stillrunning-1.9.2-py3-none-any.whl
  • Upload date:
  • Size: 57.3 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.3

File hashes

Hashes for stillrunning-1.9.2-py3-none-any.whl
Algorithm Hash digest
SHA256 873bab4469edc0fc1aecaff58c3a5af529e34fb59f59ad0bb761ff5a108efa3b
MD5 4374664da4e4afb22639c8f7c7c687da
BLAKE2b-256 6d627039b66d8abf4bcd9c675cc013824ec22020a1d4a3968c1dd8a17c71dd02

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page