Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Ask HN: Securing Pip and NPM package use?
1 point by giantg2 6 days ago | hide | past | favorite | 1 comment
Does anyone use a scanning utility to check packages for security issues? Like proxying the request through a utility that will provide some scanning before returning it.




This might not be exactly what you meant or wanted, but I use OpenSnitch, which alerts me about all new connections. I also use temporary disposable virtual machines in QubesOS to isolate those kinds of activities from my more vulnerable systems.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: