Identifying Vulnerable Source Code
Design and Architecture
1
Posts
1
Posters
0
Views
1
Watching
-
I noticed last week that the latest version of the Node Package Manager automatically audits your installation, checking installed versions against the data base of documented vulnerabilities in the NPM Registry. It delivers a very nice report, complete with instructions for automatically fixing many vulnerabilities by upgrading the affected packages. Other package managers (e. g., NuGet for Microsoft .NET, Composer for PHP, PIP for Python, PPM for Perl, would do well to implement such a feature, and probably will soon.
David A. Gray Delivering Solutions for the Ages, One Problem at a Time Interpreting the Fundamental Principle of Tabular Reporting