Hacker News new | ask | show | jobs
by thih9 1690 days ago
Does it recognize hashes of proprietary (closed source, minified) files too?
1 comments

Nope, it does not. If you remove the comment at the beginning of an unminified JS file, it will not recognize it as outdated anymore. You should treat WhiteSource as something that can potentially help to find problems, but it will by no means grant you security on its own. It is an enterprise tool to help people check boxes.
We leverage it mainly to confirm license compliance but the package vuln notifications are nice