Mmastodon TechnologySoftware first seen 7 h ago, last 7 h ago, peak #6
OpenSSF Scorecard flags package risks before advisories exist
Original: Most dependency scanners only tell you about vulnerabilities that already have an advisory filed... # opensource # secur
Security commentators are highlighting a blind spot in common dependency scanners: they only catch vulnerabilities once a formal advisory has been filed. OpenSSF Scorecard is being promoted as a complementary tool, assessing open-source packages for risky practices and structural weaknesses before any advisory is published, giving developers an earlier warning signal about the software they rely on.
Why now: Growing concern over software supply chain security and gaps in existing dependency scanning tools
OpenSSFOpenSSF ScorecardGitHub
Evidence
- Most dependency scanners only tell you about vulnerabilities that already have an advisory filed... # opensource # security # devsecops # github # software # coding # development # engineering # inclusive # community OpenSSF Scorecard explained: catching risk in packages that… · hackaday@www.urbanmind.net · 3
API: https://socialmediatrends-api.osmike.com/v1/trends/520860