3 ms·
It's not a smoking gun. It is just one of a number of signals you look for when identifying potentially malicious packages. Other things you look for are numb
by 6mile 2y ago
It's not a smoking gun. It is just one of a number of signals you look for when identifying potentially malicious packages. Other things you look for are number of collaborators, how long it existed, domains it talks to, and artifacts it pulls in.
- guappa 2y ago> are number of collaborators You have any idea how easy it is to fake it? Also, snyk doesn't scan code that isn't on github, because they are under the impression that all the code in the world is on github, so things like gnome.org, debian salsa or codeberg are completely ignored. So you won't get reliable data from snyk. edit: snyk doesn't scan code at all, they rely on unrelated "metrics" to give a rating that is not very useful.