Skip to content

Add security tools (LavaMoat, StepSecurity, Socket) #3

@shapkarin

Description

@shapkarin

Duplicates

  • I've searched existing issues and this hasn't been requested yet

Package

Not sure

Problem

A ton of supply chain attack these days.

Proposed solution

There are a bunch of great tools to prevent that:

  • LavaMoat. Provides strict policies for your dependencies (like allow only specific API) used by MetaMask (proof) and backed by Consensys
  • StepSecurity has GitHub Actions and API
  • Socket has GitHub Actions and API

Alternatives considered

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions