I built a tool for policy driven vetting of open source packages
I built a tool for policy driven vetting of open source packages
Linux Foundation survey says 70-90% of modern software constitute OSS code. Yet we are stuck with tools that scan only for vulnerabilities in 3rd party libraries and that too with high degree of false positives. I built `vet` for policy and data driven analysis of 3rd party packages that goes beyond only vulnerability and allows codifying organisational policies related to OSS consumption. https://github.com/safedep/vet Looking forward to feedback and suggestions from HN :)
Share cardActual performance
Launch Intel predictions
Analyze your own launch →Correct prediction on native model
Similar products
Open-Source Rego Policy Enforcer for Open-Policy Agent(OPA)
Open-source 3D SAT SCORM packages
oso – Open-Source Policy Engine for Authorization
I built an open-source tool to make on-call suck less
InfraGenie – open-source tool to decouple your Terraform
Open-Source Osint Tool
K4nundrum – An open-source tool to investigate Kryptos K4
CodeOrb – Open-source µC debugging tool
SpiderFoot, the open source footprinting tool
Shireframe – Open source declarative wireframing tool for programmers