The CVE Binary Tool helps you determine if your system includes known vulnerabilities. You can scan binaries for over 350 common, vulnerable components (openssl, libpng, libxml2, expat and others), or if you know the components used, you can get a list of known vulnerabilities associated with an SBOM or a list of components and versions.
仓库
ossf 的仓库
ossf/cve-bin-toolPython
(1,738 stars) (646 forks) (4 个已索引 issue) (4 个开放 good first issue)
Global CyberSecurity Skills Framework
(6 stars) (2 forks) (0 个已索引 issue) (0 个开放 good first issue)
Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption
(116 stars) (44 forks) (2 个已索引 issue) (2 个开放 good first issue)
Website and API for OpenSSF Scorecard
(29 stars) (30 forks) (8 个已索引 issue) (8 个开放 good first issue)
Our objective is to enable open source maintainers, contributors and end-users to understand and make decisions on the provenance of the code they maintain, produce and use.
(207 stars) (38 forks) (0 个已索引 issue) (0 个开放 good first issue)