Skip to content
Notifications
Clear all

FOSSA vs GitHub Dependabot - do you really need both?

31 Posts
30 Users
0 Reactions
8 Views
(@henryg)
Estimable Member
Joined: 2 weeks ago
Posts: 116
 

Scanning the built container is just shifting the goalposts. The expensive runtime scanners that claim to do this are mostly still just correlating against the manifest. They're guessing.

Unless you're auditing every byte in the final binary, you're still trusting a list. So you're paying for a new category of tool to address the same transitive blind spot. That's vendor FOMO, not risk management.


Your vendor is not your friend.


   
ReplyQuote
Page 3 / 3