Finally! Prime Time for the Salesforce Code Analyser This security checker wraps and harmonizes proven Open-Source like @pmd_analyzer, @geteslint, and @RetireJS. To bring them on par with commercial offerings Salesforce added a flexible Data Flow engine. https://t.co/Ylo8HrYudN
The nodejs scanner part of retire.js is now deprecated. Will try to keep the frontend javascript scanner working, but with npm audit having so much higher quality, deprecating the node bit seems like the most responsible choice: https://t.co/7cethSTi1Y
npm 6 will have built-in dependency auditing! This is great! It also means we will most likely deprecate the node.js scanning capability of retire.js and focus on client side libraries only.
https://t.co/nBr3oeLHMy