Npm-scan: Modern supply chain security for the npm ecosystem
Hacker News 热议:Npm-scan: Modern supply chain security for the npm ecosystem(0 赞,来源 github.com)
一句话概要
Modern supply chain security for the npm ecosystem. Static + behavioral analysis that catches what npm audit, Snyk, and Socket miss — obfuscated payloads, credential stealers, conditional triggers, sandbox evasion, and worm-like propagation. - lateos-ai/npm-scan
原文开头节选
You signed in with another tab or window. Reload to refresh your session. You signed out in another tab or window. Reload to refresh your session. You switched accounts on another tab or window. Reload to refresh your session. Dismiss alert {{ message }} Uh oh! There was an error while loading. Please reload this page .
lateos-ai / npm-scan Public Notifications You must be signed in to change notification settings Fork 2 Star 17 Use this GitHub action with your project Add this Action to an existing workflow or create a new one View on Marketplace main Branches Tags Go to file Code Open more actions menu Folders and files Name Name Last commit message Last commit date Latest commit History 217 Commits 217 Commits .github .github .husky .husky api api backend backend cli cli deploy/ helm/ npm-scan deploy/ helm/ npm-scan docker docker docs docs fixtures/ campaigns fixtures/ campaigns scripts scripts src/ config src/ config test test tests/ corpus tests/ corpus .dockerignore .dockerignore .gitignore .gitignore .npmignore .npmignore .prettierignore .prettierignore .prettierrc .prettierrc …
(以上为原文节选,完整内容见下方”原文来源”)
原文来源: Hacker News