Re: Vulnerability scanning for CNCF projects
Luke A Hinds <lhinds@...>
Add me as well. I am one of the maintainers on bandit (python ast based security linter) which hits around 25k downloads a day, so I have a fair amount of experience in what works / does not work well with security linters. As others have mentioned, false positives always happen so you need a developer UX that does not make the linter into something that gets yelled at all the time.
|
|