owasp-dep-scan / dep-scan

OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container images are supported as the input, and the tool is ideal for integration.
https://owasp.org/www-project-dep-scan/
MIT License
986 stars 97 forks source link

[risk-audit] Detect use of Trusted publisher #301

Open prabhu opened 5 months ago

prabhu commented 5 months ago

Both npm and pypi supports trusted publishing. Need to check if the data is available via the api.