| ▲ | rkozik1989 5 hours ago | |||||||
People need to do their due diligence when including open-source software and packages not just when they first use them but anytime you have a need to upgrade them. I highly doubt I'm the first one to think of this, but there really aught to be tool or comprehensive set of tools that routinely scan open-source software and packages for potentially malicious code and alert users of the problem(s). | ||||||||
| ▲ | junon 5 hours ago | parent [-] | |||||||
There are. Socket, Aikido, and a number of others do this all the time. | ||||||||
| ||||||||