Use cases / Security and platform teams

Stopping hallucinated dependencies

Slopsquatting: attackers register the package names models invent. Catch them at review.

The problem

Models confidently import packages that do not exist, and attackers now publish malware under exactly those names. A new line in requirements.txt looks harmless.

What visualdiff does

In the sample, “reqeusts” is flagged both as an imitation of requests and as absent from PyPI.

Open the sample reviewReview your own pull request

Related