File and dependency security monitor for Void Linux. Glues together ClamAV, YARA, and osv-scanner into a runit-managed daemon with a Textual TUI for reviewing results.
File scanning watches ~/Downloads, /tmp, and configured dependency directories via inotify. New files are scanned with YARA rules (Neo23x0/signature-base) and ClamAV, queued sequentially at low CPU priority to avoid impacting interactive use. Rules requiring external variables are run individually at scan time with real file metadata rather than compiled in.
Dependency scanning finds all lockfiles recursively under ~ at startup and watches them with inotify. When a lockfile changes, osv-scanner checks it against a locally cached vulnerability database. Covers mix.lock, uv.lock, requirements.txt, pnpm-lock.yaml, package-lock.json, yarn.lock, Cargo.lock, go.mod, and others.
A second runit service runs daily updates: pulls the latest signature-base, recompiles YARA rules, refreshes OSV databases via HTTP, updates ClamAV signatures with freshclam.
RAM detection at install time sets the scan mode automatically. Systems with more than 16GB use clamdscan (requires the clamd daemon, faster), others use cold clamscan.
Built around a specific workflow on Void Linux with River and mako. The code is better suited to editing for your own setup than as a finished product, but it serves as a template for users who are not used to managing threats on Linux.