4 ms·
Is this realistic though? Every time you update a dependency you would have to read its source (and its source dependencies, and their source dependencies...)
by probablycorey 8y ago
Is this realistic though? Every time you update a dependency you would have to read its source (and its source dependencies, and their source dependencies...)
To do that well, it would be someone's fulltime job to read and do security audits on all those dependencies.
- illustrioussuit 8y agoTheoretically, once something is updated all you would have to do is check the diff. Still tedious though.
- Y_Y 8y agoI look forward to all the clever exploits that result from benign-looking code being added to benign-looking code.
- komali2 8y agoLast time I went to one of the Bay Area node meetups, that given meetup was being sponsored by just such a company. Can't remember the name, unfortunately. The idea was though that you'd feed them your package.json and they'd let you know of any vulnerabilities, iirc. Or maybe they had a private repo of packages they'd checked? Can't remember.
- tomsmeding 8y agoPossibly https://snyk.io/ https://snyk.io/ ?