Vulnerability scanner written in Go that uses osv.dev data
github.com
github.com
1. https://github.com/ossillate-inc/packj flags malicious/risky packages.
This isn't available yet, but we're working on exactly this in two ways:
1. Extending our API to detect vendored C/C++ code by building an file hash index 2. Building a high quality C/C++ vulnerability database.
You can follow the two linked issues here: https://github.com/google/osv-scanner/issues/82 for updates!
Does anyone know good sources for creating a SBOM?
We open sourced a few tools that do it automatically for containers:
That said, all the Gradle projects I've used have pinned to specific versions rather than ranges.