Ask HN: How do you check for malware in OSS packages?
What tools would you suggest to scan for malicious packages or dependencies?
At work we use a commercial tool for static analysis. From what I have seen it is rather stupid, it produces a lot of false positive security issues about things like allocating memory (potential resource exhaustion vulnerability...)
You also probably want to pin versions of all dependencies, and store them in a repository that you control access to (a good idea for reproducibility, ignoring security).
[0] https://snyk.io