2 ms·
Not from what I’ve seen. What are the relevant products in this space? Can’t expect every random company to set up package scanning from scratch.
by pletnes 2y ago
Not from what I’ve seen. What are the relevant products in this space? Can’t expect every random company to set up package scanning from scratch.
- tsm 2y agoI worked for an IBM acquiree 13 years ago and as part of the "Blue-washing" process to get our software up to IBM spec we had to use their proprietary tools for verifying our dependencies were okay.
- chrisweekly 2y agoJFrog / Artifactory is one very common provider of private npm registries. There are a ton of security-scan vendors out there (mend/whitesource, socket, black duck...)
- deleted 2y ago[deleted]
- giantg2 2y agoWell then I wouldn't expect to do business with every random company. TPRM is a big issue today, so I wouldn't expect any company not performing basic due diligence to service.