Hacker News new | ask | show | jobs
by uvw 2181 days ago
I would be surprised if anyone has enough resources or willingness to do that for every open source package they are using. For companies that go through auditing, they can CTA by relying on products like Nexus IQ.