dep-scan
dep-scan copied to clipboard
OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container ima...
As per PURL spec, both these fields are optional https://github.com/package-url/purl-spec/blob/master/PURL-SPECIFICATION.rst https://github.com/DependencyTrack/dependency-track/issues/2694
No. Your SBoM, VEX and VDR is your business. I would happily reimplement any deps.dev feature that is lacking in dep-scan in a privacy-protecting manner. Thank you, Prabhu
Hi I would like to supply a file with list of assets(hardware,operating system,application) to dep-scan as input to scan for vulnerabilities and get matching vluns from NIST. a@MacBook-Air bin %...
Continuation of https://github.com/AppThreat/dep-scan/issues/79 Why can't depscan support multiple scanning engines such as dependency track and others, including commercial tools? When provided with arguments to the external scanner, the tool could...
https://blog.trailofbits.com/2023/01/13/sigstore-python/
Currently, file names are generated with a bunch of find and replace, which sometimes interferes with directory names. Eg, if the `--reports-dir` contains the word `depscan`, it gets changed to...
Well, it's time dep-scan is tested against the other tools to identify gaps. A new workflow is set up to continuously test dep-scan against top docker images. Results are then...
We should redo the HTML export logic and bring it to this project directly.
Both npm and pypi supports trusted publishing. Need to check if the data is available via the api.
### Expected Behavior Report with reachability information is produced ### Actual Behavior depscan ends with error: DEBUG [2024-04-23 06:29:51,230] BOM Profile: research DEBUG [2024-04-23 06:29:51,231] ⚡︎ Executing "cdxgen -r -t...