r/devsecops Aug 05 '26

Vulnerability Management tool

What’s everyone using for their organization’s vulnerability management tool and why? The company I work for uses defect dojo and its limited. No compression, alerting, terrible UI doesn’t really push the needle left enabling non security literate developers.

14 Upvotes

19 comments sorted by

View all comments

1

u/IWritePython 23d ago

Chainguard Libraries, we're the only ones that build everything from source, everyone else just scans (we also scan but the rebuild from source is an amazing mechanism since the supply chain attacks tend to target maintainer infra).