Interesting tool, will definitely try - just curious, is there a tool (hexora checker) that ensures that hexora itself and its dependencies are not compromised ? And of course if there is one, I'll need another one for the hexora checker....
There is no such tool, but you can use other static analyzers. Datadog also has one, but it's not AST-based.
https://xkcd.com/2044/
There is no such tool, but you can use other static analyzers. Datadog also has one, but it's not AST-based.