Ask HN: Best approach to dependency vulnerability scanning in CI?
https://news.ycombinator.com/item?id=48944189We're struggling with software supply chain security. Looking for automated vulnerability detection tools and sbom generation that don't need source code access. How are you securing software dependencies today?