As a result, the hard part is collecting info on vulnerable dependencies. We solved this problem for Ruby by… co-maintaining an open source database https://github.com/rubysec/ruby-advisory-db/ – which everyone is free to use.
We don't have the resources to do this for every community :).
BundleScout[1] does this for other languages, including Node.js and Python--and of course Ruby Gems. We don't have Github integration yet, but you can simply upload your requirements file (which, it seems, some people would rather do anyway).
1. When I upload a requirements.txt file, let me just pick 5 packages from the file instead of telling me I have to upgrade to use it.
2. Why is Django listed as the old version 1.3.7 in my dash?
3. You have a Twitter account, but there appears to be no link on your website that I could spot.
1. We just pushed the import feature a couple days ago so we're still tweaking how it works. This is a good suggestion, I'll definitely take it into consideration.
2. You should be seeing 1.3.7 as the 'old version' (last update we detected). We're still working on better branch/track breakdown--this isn't an issue for most packages.
3. The Twitter account is linked at the bottom of the page :)
Let me know at friends [at] bundlescout [.] com if you're not seeing the right Django version and I'll look into it today.
Congrats on a cool product and I'm glad it was posted here.