osv-scanner
osv-scanner copied to clipboard
Support scanning remote OS
With the merging of https://github.com/google/osv-scanner/pull/168 there is now local OS scanning. What could be done to add functionality to do remote OS scanning?
- Connect over SSH(or other?)
- Get the required output
-
- No install on remote host required
- Generate report on the local machine
This is basically how VULS does it.
Being able to scan a fleet of remote hosts for newly discovered CVEs in existing installs seems like a really useful feature.
That being said, I don't know Golang and don't know the internals of either this project or VULS. And I have no free time to dedicate myself to it.
I'm putting this up as a suggestion. If time nor resources currently exist for this feature, then I suppose the first step would be to park this.
Thank you for your time, and feel free to close and/or remake this request by someone of the team(is there a team?) if the consensus is that's easier to have this idea picked up in earnest that way.
This issue has not had any activity for 60 days and will be automatically closed in two weeks
This issue has not had any activity for 60 days and will be automatically closed in two weeks
See https://github.com/google/osv-scanner/blob/main/CONTRIBUTING.md for how to contribute a PR if you're interested in helping out.
Automatically closing stale issue