-
Notifications
You must be signed in to change notification settings - Fork 13
Open
Labels
enhancementNew feature or requestNew feature or request
Description
When using a package manager like PIP or NPM, these don't check for vulnerabilities and can compromise the environment. We need to build a plugin which would block the installation of compromised dependencies.
The tool would observe the onchain data for that and would be able to block dependencies which do not respect a certain level of security. Eg accept low CVEs or only block criticals.
Metadata
Metadata
Assignees
Labels
enhancementNew feature or requestNew feature or request