3 pointsby ductrl3 hours ago2 comments
  • buffer_overlord2 hours ago
    Vu1nz does something similar but at the PR level
    • ductrl2 hours ago
      I am aware of existing tools doing the same thing at the PR level. I wanted to create a tool for commits since it is when the changes enter Git history.

      I am also wondering if it makes more sense to have the tool check right before a push instead since that's when the vulnerabilities actually get sent to the Internet

      • buffer_overlordan hour ago
        The problem for me was contributions I was getting 183 a day and couldn’t figure out what was malware and what was legit so my friend built me vu1nz
  • speedwoof3 hours ago
    [dead]