Register and share your invite link to earn from video plays and referrals.

Leif Dreizler
@leifdreizler
Eng Manager at @semgrep ๐Ÿ’ป co-host of @404pod ๐ŸŽ™
1.6K Following    2.1K Followers
Many malicious packages get caught within a few days or even a few hours. Your org rarely needs a dependency version released that recently. A one week cooldown offers a strong security ROI with minimal developer friction.
Show more
Malicious Python and JavaScript deps have dominated this year's supply chain news cycle, but how many of y'all still have pinning GitHub Actions on your to do list? Hereโ€™s how I did this org-wide at Semgrep.
Show more