vulncost
vulncost copied to clipboard
Find security vulnerabilities in open source npm packages while you code
I hope some body give us the freedom to check known vulnerability in #Dockerfile for image building and shows hint how to remediate them maybe as an extension for VS...
# What did you expect? IDE plugin to be aware of settings in the `.snyk` file. # What did you experience? Vulns reported in IDE, even though set to ignore...
Using this version of tap and there's definitely not that many vulns: https://snyk.io/test/npm/[email protected] - what's strange too is that the local machine report doesn't even match the online test (locally...
Currently it seems to run whenever it sees an import. That includes also read-only diff views and also both sides, that seems highly unnecessary since depending on the commit you...
_Vuln cost_ and _[Import cost](https://marketplace.visualstudio.com/items?itemName=wix.vscode-import-cost)_ use the same UX, as they add some infos (eg: calculating, result) after the imports, on the same line. But depending on the launch order...