Hacker News new | ask | show | jobs
by spatulon 3138 days ago
This is something that lgtm.com supports. Right now, I can't find a Python project with a dependency on a vulnerable package to show you, but here's the page that shows Django's dependencies (and this is where a known vulnerable version would be highlighted).

https://lgtm.com/projects/g/django/django/dependencies