google / vanirLinks
Vanir is a source code-based static analysis tool that automatically identifies the list of missing security patches in the target system. By default, Vanir pulls up-to-date CVEs from Open Source Vulnerabilities (OSV) together with their corresponding signatures so that users can transparently scan missing patches for an up-to-date list of CVEs.
☆349Updated 3 months ago
Alternatives and similar repositories for vanir
Users that are interested in vanir are comparing it to the libraries listed below
Sorting:
- OSV-SCALIBR: A library for Software Composition Analysis☆561Updated last week
- A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerabilit…☆449Updated this week
- AI-Native Static Code Analysis for modern security teams. Built for finding vulnerabilities, advanced structural search, derive insights …☆97Updated this week
- Metis is an open-source, AI-driven tool for deep security code review☆461Updated last week
- blint is a Binary Linter that checks the security properties and capabilities of your executables. It can also generate a Software Bill-o…☆432Updated 2 months ago
- atom is a novel intermediate representation for applications and a standalone tool that is powered by chen.☆84Updated this week
- An open-source dataset of malicious software packages found in the wild, 100% vetted by humans.☆300Updated last week
- Prevent merging of malicious code in pull requests☆252Updated 3 weeks ago
- Focused malicious code detection ruleset, with a high protection-to-noise ratio☆141Updated 11 months ago
- Securing open-source package ecosystems by originating, validating, and augmenting build attestations.☆677Updated this week
- GuardDog is a CLI tool to Identify malicious PyPI and npm packages☆960Updated last week
- A comprehensive list of software composition analysis tools.☆162Updated 3 months ago
- A very simple open source implementation of Google's Project Naptime☆184Updated 10 months ago
- Deep Linux runtime visibility meets Wireshark☆302Updated 2 months ago
- Open Source Vulnerability schema.☆230Updated this week
- CI/CD Security Analyzer☆729Updated 11 months ago
- Autogrep automates Semgrep rule generation and filtering by using LLMs to analyze vulnerability patches, enabling automatic creation of h…☆72Updated 11 months ago
- SAST + LLM Interprocedural Context Extractor