6 ms·
How did you guys detect it? Do you use it internally or do you monitor popular packages?
by janice1999 4mo ago
How did you guys detect it? Do you use it internally or do you monitor popular packages?
- varunsharma07 4mo agoWe have built an AI Package Analyst https://app.stepsecurity.io/oss-security-feed https://app.stepsecurity.io/oss-security-feed and also monitor them using https://github.com/step-security/harden-runner https://github.com/step-security/harden-runner for runtime behavior.