Hacker News new | ask | show | jobs
by rkozik1989 3 hours ago
People need to do their due diligence when including open-source software and packages not just when they first use them but anytime you have a need to upgrade them. I highly doubt I'm the first one to think of this, but there really aught to be tool or comprehensive set of tools that routinely scan open-source software and packages for potentially malicious code and alert users of the problem(s).
1 comments

There are. Socket, Aikido, and a number of others do this all the time.
Step-Security, Wiz ..