At a glance
- Malicious and vulnerable packages get stopped at install, on every device in the company, including those of non-engineers writing code with AI tools
- Dependency and container scanning runs across all repositories and containers
- A required Aikido check in GitHub blocks vulnerable code from reaching production
- Developers stay in their normal workflow instead of learning another tool
- Aikido feeds the compliance chain, creating dated tickets and making missed SLAs more visible
The new risk was open source, and the old setup only watched production
Too Good To Go, the company behind the world's largest marketplace for surplus food, uses Aikido to catch malicious and vulnerable open source packages before they reach a developer device or production, and to keep its security work tied to compliance.
Robert Christiansen, VP of engineering, is responsible for engineering, developer experience, and compliance across the company's software teams. Too Good To Go has run its surplus-food marketplace since 2015, and now connects more than 120 million users with partner stores across 21 countries, all supported by an engineering organization inside a roughly 1,300 person company.
A year and a half ago, the team's priority was stopping infected libraries before they reached production. Over the past six months, attacks on open source packages and on the developers who install them have increased rapidly, and open source projects are getting hammered with new vulnerabilities. The bigger risk now sits earlier in the chain: a package that compromises a developer's device before anything ships. Developers usually hold more access than anyone else, which makes their devices the most valuable target.
The exposure also spread beyond engineering. People in other business functions have started writing code with AI tools, pulling Node and Python packages onto devices no security process was built around. Robert calls that even more dangerous. The team's existing tools only scanned after the build. That protected production and left development open.
Compliance raised the stakes further. Too Good To Go works to NIS2 and PCI, and PCI sets its own requirements on how fast the team has to react to a vulnerability. The team needed one product that could stop problems on the device and at build time, and prove the follow-up happened on schedule.
One tool from the device to the pipeline
Aikido Safe Chain now runs on every device across the organization. It checks whether Node or Python is installed and guards the install step, so a bad package gets stopped before it lands, whoever is installing it. Device protection covers the roughly 160 people the company classifies as engineering, whether they write code or not.
In the pipeline, every change has to pass an Aikido check in GitHub before it can go to production. Because the check sits inside the normal development flow, security never turns into a separate step someone has to remember. Aikido tracks vulnerable dependencies and container images across just under 200 repositories and more than 200 containers, including the deep chains of transitive dependencies that even hardened Docker images carry.
The developers whose job is upgrading libraries use the IntelliJ plugin to see whether a finding is a real issue and whether an update is likely to break something before they touch it.
Developers don't even need to go into Aikido all the time. It's just become part of the workflow.
Why Too Good To Go chose Aikido
- Protection on the device and at build time (the two places the old setup left open)
- A quick, low-effort setup
- A simple UI and transparent pricing
Aikido catches what would otherwise get through
The biggest change is what no longer slips past. Safe Chain and device protection have already stopped packages on developer devices, and when Robert is asked whether Aikido catches real threats, his answer is "most definitely, it is catching things that otherwise would go through."
We now have full visibility into what libraries we need to fix, both for the infrastructure and the code.
Robert counts one business result above the rest: the team hasn't had an incident from a compromised library.
On the compliance side, Aikido creates tickets marked with dates, so when a fix falls behind its SLA, everyone can see it right away. With PCI setting firm expectations on response times, that record helps Too Good To Go stay compliant without chasing status by hand.
How Too Good To Go uses Aikido today
Currently using
- Dependency scanning
- Container scanning
- Aikido Safe Chain organization-wide
- Device protection across engineering
- GitHub pipeline check
- The IntelliJ plugin for the developers doing fixes
Planning next
- A severity model that maps each finding to its real exposure, so internal services with no internet access get patched on a monthly cycle while exposed ones get fixed right away
Evaluating
- AI pentesting, which the team's security engineer wants to test, so they can run automated tests more often alongside the pentests they already run each year
Final verdict
The product was easy to set up, and it works. I'm glad we did it and I would have loved to have had it earlier.


