
Typosquatt alert ! Malicious npm Package: nyc-config
Possible typosquatting against @istanbuljs/load-nyc-config with ~25M weekly downloads.
Follow for the latest updates and insights on
open source security & engineering.

Possible typosquatting against @istanbuljs/load-nyc-config with ~25M weekly downloads.

SafeDep Code Analysis framework augments vet, our free and open source tool with code context.

Introducing vetpkg.dev - Built using SafeDep API to provide an easy to use visibility of open source component security information.

Software Composition Analysis has been there for a while. But the problems associated with open source vulnerabilities persist. Next-gen SCA is the promised solution. What is it and how does it work?

Install the SafeDep GitHub App to keep malicious packages out of your repos.
