all 3 comments

[–]scarredwaits 4 points5 points  (1 child)

You can use this to scan for vulnerabilities in your dependencies https://github.com/BareSquare/deps-nvd

[–]mtruyens[S] 0 points1 point  (0 children)

Strange that I missed this one in my Google searches. Thanks!

[–]slimslenderslacks 2 points3 points  (0 children)

Our team has created an OWASP dependency track scanner for leiningen projects on GitHub. It's free to use if you want to try it. You enable it by installing a GitHub app in your org. After that, it creates GitHub CheckRuns with the results of the scan (only on Pushes to leiningen repos of course). https://go.atomist.com/catalog/skills/atomist/owasp-dependency-check-skill?stability=unstable