#dependency-scanning

[ follow ]
Information security
fromTheregister
3 days ago

Socket will block it with free malicious package firewall

Socket released Socket Firewall Free, a free CLI that blocks malicious dependencies at install time across npm, yarn, pnpm, pip, uv, and cargo.
Software development
fromAzure DevOps Blog
1 month ago

Automate your open-source dependency scanning with Advanced Security - Azure DevOps Blog

GitHub Advanced Security simplifies the enablement of dependency scanning in Azure DevOps pipelines for enterprise-level security.
DevOps
fromAzure DevOps Blog
4 months ago

One Pipeline to Rule Them All: Ensuring CodeQL Scanning Results and Dependency Scanning Results Go to the Intended Repository - Azure DevOps Blog

Configure your pipeline to ensure scan results are published to the intended repository.
[ Load more ]