Repository Details
Shared by


HelloGitHub Rating
0 ratings
Tool for Detecting Vulnerabilities in Project Dependencies
Past 6 days Received 12 stars ✨
Free•Apache-2.0
Claim
Discuss
Collect
Share
7.1k
Stars
No
Chinese
Java
Language
Yes
Active
304
Contributors
378
Issues
Yes
Organization
12.1.3
Latest
1k
Forks
Apache-2.0
License
More

This project is a Software Composition Analysis (SCA) tool written in Java, designed to identify and report security vulnerabilities in project dependencies. It uses Common Platform Enumeration (CPE) identifiers to recognize known vulnerabilities in project dependency libraries, thereby generating detailed security reports and linking to relevant CVE entries. The tool supports the analysis of dependencies for a variety of programming languages and frameworks and can be seamlessly integrated into existing build processes.
Comments
Rating:
No comments yet