Vulnerable Method detection now available on SourceClear for Python projects
blog.sourceclear.com
blog.sourceclear.com
When you scan your python projects now, we can actually tell you if you have a call chain to those particular methods in the vulnerable library or not.
Most security tools aim to scare people about the sky falling. Here we're taking a saner approach and letting you know if you're directly impacted by a vulnerability or not, so you can update at a more leisurely pace.
Maybe this is something like functions calls which use improper sql escaping? I am not sure what is being detected.
Here's an example of some vulnerabilities that we discovered, disclosed, and now have in our database: https://blog.sourceclear.com/copy-paste-vulnerability-disclo...
The full vulnerability database is online here: https://www.sourceclear.com/registry/explore