Snyk.io – Find and fix known vulnerabilities in Node.js dependencies
snyk.io
snyk.io
> by uploading or posting content to the Platform and providing access to your system’s source code repository, you hereby grant to Snyk, limited to the extent it is necessary in order to enable your use of the Platform, a perpetual, worldwide, non-exclusive, royalty free and transferable licence (with right to sub-license) to, including without limitation, use, display and transmit the content and source code
.. No thanks.
A service allowing consumers to "find and fix known vulnerabilities in Node.js dependencies" certainly does not require a transferable license (especially one with the right to sub-license). A transferable license allows the licensee to freely assign the license to any other party without the licensor's consent. The wording includes the right to sub-license, allowing the same license to be granted to another third-party -- again, without the need to obtain the licensor's consent due to its inclusion as part of the transferable license statement.
The Node.js ecosystem is still fairly immature with regard to formalized security, certainly in comparison to, say, the Java ecosystem. There just aren't as many people filing CVEs on packages as a part of vetting their stacks, and certainly far fewer people focused on that part of the security process.
To a certain degree tools are only going to be as good as the security environment. If people aren't filing CVEs at an appropriate pace given the level of vulnerability out there, and it takes a village, etc, etc, then no one group is going to be able to deliver a good security service on their own, since these services are individually (a) a megaphone and filter for a CVE RSS feed, and (b) a minor source of CVEs.