Breaking Bad (Packages): Why Traditional Vulnerability... - Shelby Cunningham and Madison Ficorilli
PyCon US · 29:48
Traditional CVE and GitHub advisory pipelines were built for accidental vulnerabilities, not malware or multi-ecosystem supply-chain compromises, so they systematically miss, delay, or fragment the alerts defenders ne...