We quietly released the code a little while ago but this is the official announcement of Capslock, our contribution to the supply-chain security conversation.
https://security.googleblog.com/2023/09/capslock-what-is-your-code-really.html
Capslock is a tool for understanding at high level what a given piece of (Golang) code is capable of and for detecting when an update to a library changes this capability set, to give users a chance to catch supply-chain attacks in progress.
1/2