• These tools aren’t suitable to run on software repositories automatically, in large part because they’re too noisy.
  • External researchers can (and do) run their own tools in their own environments and send reports to get malware removed.
  • This often works out better for everybody involved.
  • There are promising directions for improving these scanners, and other, even more promising techniques for improving software repository security that administrators are working toward right now.