|
|
|
|
|
by toomuchtodo
526 days ago
|
|
One of my responsibilities is software supply chain security in a financial services org, so this signal would be valuable for vulnerability management of dependencies. I wouldn't call it "threat hunting" per se, but ground truth around threat actor patterns helps us build better defensive systems in this regard. Keeping the bad bits out is way easier than remediating once they've been ingested into systems. > Your comment also has me dreaming about a Dependabot-esque utility that opens Github issues on repositories that have quarantined projects in their requirements.txt. It's not a bad idea, let Github know! Their security team is very good from my interactions with them. |
|
Lowkey surprised that any well-resourced org would use it given the outsized risk profile and poor performance.