Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
ozim
4 months ago
|
parent
|
context
|
favorite
| on:
Oh no, not again a meditation on NPM supply chain ...
Have you tried Dependency Track from OWASP? Generate SBOM from each repo/projects and post it with API to DT and you have full overview. You have to hook it up so it is done automatically because of course stuff will always move.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: