This year's SOC-2 audit is even worse than last year.
I got a not so technical auditor and it's hard to explain why git repository with no code but critical in other way does not have dependency CVE scan enabled.
Any recommendations for next year's SOC-2 auditor ?

Hacker News