Open Source

Open Source articles

Architecture, maintainer signals, and migration risks for tools worth adopting.

Open Source Lead story

OSV-Scanner works best when vulnerability scanning stays close to dependency evidence

An architecture note on OSV-Scanner, arguing that its useful boundary is evidence-first vulnerability matching: extract packages from lockfiles, manifests, SBOMs, source trees, and container artifacts; match them against OSV's package-and-commit-aware database; then use configuration, call analysis, and remediation as triage layers rather than treating scanner output as a finished risk decision.

All articles

238 total