Hacker News new | ask | show | jobs
by outloudvi 12 days ago
I think it's great if people actually use LLM for the analysis. I did mention it in the solution part in the post:

> Run LLM-assisted audit on vendored code.

1 comments

What do you call the time period between "new package is released" and "automated security scanners have analyzed the package"? That sure sounds like a release cooldown to me.
I applaud you if you do setup automated security scanners, without counting on external security groups or individuals (that doesn't have a security contract with your company).

This post is based on an assumption from what I see (I would be very happy if it's wrong) that most companies do not event bother to do these scans. They are merely waiting for the free kindness.