MikeTrendsTrends right now

search

OpenSSF

Trends

  1. 1
    OpenSSF Scorecard flags package risks before advisories exist●Most dependency scanners only tell you about vulnerabilities that already have an advisory filed... # opensource # securMmastodonTechnologySoftware31 d ago

    Security commentators are highlighting a blind spot in common dependency scanners: they only catch vulnerabilities once a formal advisory has been filed. OpenSSF Scorecard is being promoted as a complementary tool, assessing open-source packages for risky practices and structural weaknesses before any advisory is published, giving developers an earlier warning signal about the software they rely on.