Eliminating SCA Noise using Dependency Usage Evidence
SafeDep Code Analysis framework augments vet, our free and open source tool with code context.
Follow for the latest updates and insights on
open source security & engineering.
SafeDep Code Analysis framework augments vet, our free and open source tool with code context.
Multiple npm packages impersonating popular package names were published to the npm registry including by a Snyk researcher apparently targeting internal packages at Cursor AI.
Malware hidden in open source library packages are real. In this article, we analyse the malicious npm package llm-oracle.
Software Composition Analysis has been there for a while. But the problems associated with open source vulnerabilities persist. Next-gen SCA is the promised solution. What is it and how does it work?
Multiple npm packages impersonating popular package names are being used to distribute malware. We take a closer look at the campaign.
Start free with open source tools on your machine. Scale to a unified platform for your organization.
SafeDep keeps analytics anonymous and cookie-free until you opt in. Accepting helps us understand product usage and improve your experience. Privacy Policy
Choose what you share. You can change this anytime from the footer.