Hacker News new | ask | show | jobs
by Pepe1vo 845 days ago
We use Semgrep Supply Chain at work and are reasonably satisfied with it. It splits the supply chain vulnerabilities it found into the categories: reachable, unreachable and undetermined. This makes triaging much easier and it has reduced the time we spent on assessing new vulnerabilities by quite a lot.