←back to thread

439 points david927 | 1 comments | | HN request time: 0.444s | source

What are you working on? Any new ideas which you're thinking about?
1. abhisek ◴[] No.44420328[source]
I am working on a next-gen software composition analysis tool that can identify malicious open source packages through code analysis. Adopts a policy as code (CEL) approach to build security guardrails against risky OSS components using opinionated policies.

GitHub: https://github.com/safedep/vet