Dependency CI reviews potential vulnerabilities for open-source projects

The founder of an open-source library discovery service launched a new project today that can continuously test open-source dependencies for potential vulnerabilities and other issues. The project is Dependency CI, an open-source tool that integrates directly into a GitHub workflow just like other CI systems. It runs a set of configurable tests on any dependency … continue reading

SD Times Blog: A giant trough of open-source libraries

This weekend, I stumbled across a relatively new site: It's a massive database of programming libraries, sorted by language, platform and license. As this is a large well from which to draw software development goodness, I thought we'd drop in a bucket and see what they had to offer. A cursory glance through the … continue reading