awslabs / awslabs/simple-code-scanning-pipeline

Review Combobulator to see if it would make sense to add

Open
#18 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
19
Forks
3
PR merge metrics
No merged PRs in 30d

Description

https://github.com/apiiro/combobulator

Dependency Combobulator is an Open-Source, modular and extensible framework to detect and prevent dependency confusion leakage and potential attacks. This facilitates a holistic approach for ensuring secure application releases that can be evaluated against different sources (e.g., GitHub Packages, JFrog Artifactory) and many package management schemes (e.g., ndm, maven).

```
git clone https://github.com/apiiro/combobulator.git
pip install -r requirements.txt
python3 combobulator
```

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the Combobulator repository linked in the issue, then run the listed git clone, pip install, and python3 commands. Determine whether its dependency-confusion checks and supported package sources and managers fit this project; done means recording a clear integration recommendation and scope.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.