3 ms·
You might also look at https://github.com/nodesecurity/nsp https://github.com/nodesecurity/nsp The Node.js ecosystem is still fairly immature with regard to fo
by exratione 11y ago
You might also look at https://github.com/nodesecurity/nsp https://github.com/nodesecurity/nsp
The Node.js ecosystem is still fairly immature with regard to formalized security, certainly in comparison to, say, the Java ecosystem. There just aren't as many people filing CVEs on packages as a part of vetting their stacks, and certainly far fewer people focused on that part of the security process.
To a certain degree tools are only going to be as good as the security environment. If people aren't filing CVEs at an appropriate pace given the level of vulnerability out there, and it takes a village, etc, etc, then no one group is going to be able to deliver a good security service on their own, since these services are individually (a) a megaphone and filter for a CVE RSS feed, and (b) a minor source of CVEs.