Shameless plug: This is what I’m building Socket.dev to solve.
Socket watches for changes to “package manifest” files such as package.json, package-lock.json, and yarn.lock. Whenever a new dependency is added in a pull request, Socket analyzes the package's behavior and leaves a comment if it is a security risk.
You can see some real-world examples here: https://socket.dev/blog/socket-for-github-1.0