Repository Details
Shared by
HelloGitHub Rating
0 ratings
Tool for Detecting Vulnerabilities in Project Dependencies
Past 6 days Received 16 stars ✨
Free•Apache-2.0
Claim
Discuss
Collect
Share
6.6k
Stars
No
Chinese
Java
Language
Yes
Active
291
Contributors
505
Issues
No
Organization
11.1.1
Latest
1k
Forks
Apache-2.0
License
More
This project is a Software Composition Analysis (SCA) tool written in Java, designed to identify and report security vulnerabilities in project dependencies. It uses Common Platform Enumeration (CPE) identifiers to recognize known vulnerabilities in project dependency libraries, thereby generating detailed security reports and linking to relevant CVE entries. The tool supports the analysis of dependencies for a variety of programming languages and frameworks and can be seamlessly integrated into existing build processes.
Comments
Rating:
No comments yet