Package registries

Package registries like npm and PyPI contain many packages, each with a dependency tree, and potential vulnerabilities.