OpenSSF Scorecard explained: catching risk in packages that don't have a CVE yet
Most dependency scanners only tell you about vulnerabilities that already have an advisory filed against them. That's useful, but it's inherently reactive — it only catches risk after someone has foun
depwarden.hashnode.dev4 min read