google / vanirLinks
Vanir is a source code-based static analysis tool that automatically identifies the list of missing security patches in the target system. By default, Vanir pulls up-to-date CVEs from Open Source Vulnerabilities (OSV) together with their corresponding signatures so that users can transparently scan missing patches for an up-to-date list of CVEs.
☆341Updated 2 months ago
Alternatives and similar repositories for vanir
Users that are interested in vanir are comparing it to the libraries listed below
Sorting:
- OSV-SCALIBR: A library for Software Composition Analysis☆516Updated last week
- A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerabilit…☆384Updated this week
- atom is a novel intermediate representation for applications and a standalone tool that is powered by chen.☆71Updated last week
- Securing open-source package ecosystems by originating, validating, and augmenting build attestations.☆657Updated this week
- Prevent merging of malicious code in pull requests☆236Updated 6 months ago
- BLint is a Binary Linter to check the security properties, and capabilities in your executables. Since v2, blint is also an SBOM generato…☆407Updated last week
- Deep Linux runtime visibility meets Wireshark☆293Updated 2 months ago
- Focused malicious code detection ruleset, with a high protection-to-noise ratio☆127Updated 7 months ago
- 🧪 Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.☆41Updated 10 months ago
- An open-source security suite aiming to combine structural code analysis with AI-powered vulnerability detection. Built for advanced stru…☆81Updated this week
- io_uring based rootkit☆238Updated 5 months ago
- CI/CD Security Analyzer☆675Updated 7 months ago
- Trail of Bits Testing Handbook☆82Updated 2 weeks ago
- A comprehensive list of software composition analysis tools.☆156Updated last year
- A very simple open source implementation of Google's Project Naptime☆170Updated 6 months ago
- GuardDog is a CLI tool to Identify malicious PyPI and npm packages☆843Updated this week
- Tooling backed by an LLM for performing natural language searches against compiled target binaries. Search for encryption code, password …☆162Updated last year
- tool designed for identifying vulnerabilities in open source codebases at scale. It can gather and filter on key repository metrics such …☆234Updated 8 months ago
- Autogrep automates Semgrep rule generation and filtering by using LLMs to analyze vulnerability patches, enabling automatic creation of h…☆51Updated 7 months ago
- Protect against malicious open source packages 🤖☆802Updated last week
- An open-source dataset of malicious software packages found in the wild, 100% vetted by humans.☆244Updated this week
- A repo to conduct vulnerability enrichment.☆688Updated this week
- ☆89Updated 8 months ago
- ☆311Updated 3 months ago
- Deptective automatically determines the native dependencies required to run any arbitrary program or command.☆121Updated last month
- ☆84Updated 3 months ago
- Community reconstruction of the legacy JSON NVD Data Feeds. This project uses and redistributes data from the NVD API but is neither endo…☆181Updated this week
- Macaron is an extensible supply-chain security analysis framework from Oracle Labs that supports a wide range of build systems and CI/CD …☆173Updated this week
- A compilation of Software Supply Chain Security resources including initiatives, standards, regulations, organizations, vendors, tooling,…☆137Updated last year
- CodeQL queries developed by Trail of Bits☆129Updated last month