awslabs / awslabs/simple-code-scanning-pipeline
Review Combobulator to see if it would make sense to add
- Dominant language
- TypeScript
- Stars
- 19
- Forks
- 3
- PR merge metrics
- No merged PRs in 30d
Description
https://github.com/apiiro/combobulator
Dependency Combobulator is an Open-Source, modular and extensible framework to detect and prevent dependency confusion leakage and potential attacks. This facilitates a holistic approach for ensuring secure application releases that can be evaluated against different sources (e.g., GitHub Packages, JFrog Artifactory) and many package management schemes (e.g., ndm, maven).
```
git clone https://github.com/apiiro/combobulator.git
pip install -r requirements.txt
python3 combobulator
```
Contributor guide
Research direction
Start by reviewing the Combobulator repository linked in the issue, then run the listed git clone, pip install, and python3 commands. Determine whether its dependency-confusion checks and supported package sources and managers fit this project; done means recording a clear integration recommendation and scope.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python
- Domain
- security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100