PREPRINT: Can the OpenSSF Scorecard be used to measure the security posture of npm and PyPI?

08/06/2022
by   Nusrat Zahan, et al.
0

The OpenSSF Scorecard project is an automated tool to monitor the security health of open source software. We used the tool to understand the security practices and gaps in npm and PyPI ecosystems and to confirm the applicability of the Scorecard tool.

READ FULL TEXT

Please sign up or login with your details

Forgot password? Click here to reset