logoalt Hacker News

SamuelAdamsyesterday at 10:11 PM2 repliesview on HN

What’s nice about Dependabot is that it works across multiple languages and platforms. Is there an equivalent to govulncheck for say NPM or Python?


Replies

mirashiiyesterday at 10:53 PM

> Is there an equivalent to govulncheck for say NPM or Python?

There never could be, these languages are simply too dynamic.

show 4 replies
tech2yesterday at 11:20 PM

For python maybe pip-audit, and perhaps bandit for a little extra?

It doesn't have the code tracing ability that my sibling is referring to, but it's better than nothing.