google / vanirLinks
Vanir is a source code-based static analysis tool that automatically identifies the list of missing security patches in the target system. By default, Vanir pulls up-to-date CVEs from Open Source Vulnerabilities (OSV) together with their corresponding signatures so that users can transparently scan missing patches for an up-to-date list of CVEs.
☆343Updated 2 months ago
Alternatives and similar repositories for vanir
Users that are interested in vanir are comparing it to the libraries listed below
Sorting:
- OSV-SCALIBR: A library for Software Composition Analysis☆543Updated this week
- A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerabilit…☆425Updated this week
- blint is a Binary Linter that checks the security properties and capabilities of your executables. It can also generate a Software Bill-o…☆428Updated 3 weeks ago
- GuardDog is a CLI tool to Identify malicious PyPI and npm packages☆879Updated 2 weeks ago
- Metis is an open-source, AI-driven tool for deep security code review☆407Updated this week
- Securing open-source package ecosystems by originating, validating, and augmenting build attestations.☆673Updated this week
- Focused malicious code detection ruleset, with a high protection-to-noise ratio☆137Updated 9 months ago
- Prevent merging of malicious code in pull requests☆250Updated 9 months ago
- A very simple open source implementation of Google's Project Naptime☆176Updated 8 months ago
- io_uring based rootkit☆244Updated 7 months ago
- An open-source dataset of malicious software packages found in the wild, 100% vetted by humans.☆268Updated last week
- An open-source security suite aiming to combine structural code analysis with AI-powered vulnerability detection. Built for advanced stru…☆83Updated this week
- A repo to conduct vulnerability enrichment.☆703Updated this week
- Deep Linux runtime visibility meets Wireshark☆297Updated last month
- CI/CD Security Analyzer☆726Updated 9 months ago
- Vulnerability database and package search for sources such as Linux, OSV, NVD, GitHub and npm. Powered by sqlite, CVE 5.2, purl, and vers…☆132Updated last week
- Community reconstruction of the legacy JSON NVD Data Feeds. This project uses and redistributes data from the NVD API but is neither endo…☆191Updated this week
- #supply #chain #attack #detection☆629Updated this week
- ClusterFuzzLite - Simple continuous fuzzing that runs in CI.☆512Updated 2 weeks ago
- A comprehensive list of software composition analysis tools.☆159Updated 2 months ago
- Open Source Package Analysis☆857Updated 8 months ago
- atom is a novel intermediate representation for applications and a standalone tool that is powered by chen.☆78Updated this week
- ☆122Updated this week
- Vulnerability-Lookup facilitates quick correlation of vulnerabilities from various sources, independent of vulnerability IDs, and streaml…☆421Updated this week
- 🧪 Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.☆41Updated last year
- Tooling backed by an LLM for performing natural language searches against compiled target binaries. Search for encryption code, password …☆164Updated last year
- Deptective automatically determines the native dependencies required to run any arbitrary program or command.☆126Updated 2 weeks ago
- ☆85Updated last month
- A compilation of Software Supply Chain Security resources including initiatives, standards, regulations, organizations, vendors, tooling,…☆138Updated last year
- Callisto - An Intelligent Binary Vulnerability Analysis Tool☆368Updated 2 years ago