OSV-SCALIBR: Extensible Tool for Vulnerability Detection in Software Inventories

OSV-SCALIBR is an extensible software composition analysis (SCA) tool designed for scanning software inventories and detecting vulnerabilities. It can be used as a standalone binary or integrated as a library in Go projects. The tool supports custom plugins and enables scanning of container images or remote hosts. Users can configure extraction and detection plugins and analyze results in a predefined format. 

https://github.com/google/osv-scalibr

Comments

Popular posts from this blog

Secure Vibe Coding Guide: Best Practices for Writing Secure Code

OWASP SAMM Skills Framework Enhances Software Security Roles

Opengrep: Open-Source SAST for Code Security and Innovation