Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You don't need to pay anyone for this service. GitHub and Snyk use free public vulnerability lists to check your dependencies.

There are plenty of open source alternatives such as https://github.com/RetireJS/retire.js for JavaScript.

It's absurd that companies are charging $100/mo just to run your dependency list against another public list of vulnerabilities. This service should be offered for free by GitHub.



This _is_ free from GitHub. At least there's no mention of price in the blog post. I seem to have this feature.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: