May 29, 2024, 11:07 p.m. | Ariel

DEV Community dev.to

Using data from the open source OSV.dev project and other sources, Minder can now block pull requests that contain malicious and deprecated packages, so that they can’t inadvertently be merged into your code.


Most teams today use vulnerability scanners to find CVEs in their open source dependencies. While avoiding dependencies with known vulnerabilities is important, these scanners may neglect to flag malicious or deprecated packages that don’t have any CVEs, even though these packages may pose an even greater threat …

block blocking can code cves data dependencies dev find malicious open source opensource osv packages project pull requests requests scanners security teams today vulnerability vulnerability scanners

Ground Systems Engineer - Evolved Strategic SATCOM (ESS)

@ The Aerospace Corporation | Los Angeles AFB

Policy and Program Analyst

@ Obsidian Solutions Group | Rosslyn, VA, US

Principal Network Engineering

@ CVS Health | Work At Home-California

Lead Software Engineer

@ Rapid7 | NIS Belfast

Software Engineer II - Java

@ Rapid7 | NIS Belfast

Senior Software Engineer

@ Rapid7 | NIS Belfast