José Pedro Mayo · @jpmayo
6 followers · 14 posts · Server infosec.exchange

GitHub - google/osv-scanner: Vulnerability scanner written in Go which uses the data provided by osv.dev github.com/google/osv-scanner

#opensource #vulnerabilityscanner #google #go #osvscanner

Last updated 2 years ago

Back then · @space84
2 followers · 5 posts · Server infosec.exchange

Das möchte ich mal testen.

"Use OSV-Scanner to find existing vulnerabilities affecting your project's dependencies."

github.com/google/osv-scanner

#security #osvscanner #dependencycheck #securityscanning

Last updated 2 years ago

Ricky · @ricky
11 followers · 9 posts · Server infosec.exchange

Is this a tool that can help with web app pentesting? What would you use it for?
osv.dev/

#osvscanner #google

Last updated 2 years ago

Ricky · @ricky
11 followers · 17 posts · Server infosec.exchange

Is this a tool that can help with web app pentesting? What would you use it for?
osv.dev/

#osvscanner #google

Last updated 2 years ago

Pauli P. · @pauli
1 followers · 2 posts · Server infosec.exchange

One of those days… Trying out the new OSV Scanner (security.googleblog.com/2022/1) by going first for the Windows executable release version of it, finding out that of course its not signed and then AV says ”thou shall not pass”.

Trusting person as I am, went for the Linux version which of course worked as a charm. Interesting looking dependency scanner though not happy of the default visual output because it completely ignores the severity of the finding. Absolutely no indication if the finding is critical, low or something in between.

#osvscanner

Last updated 2 years ago

OSV-Scanner:
➡️ Find existing vulnerabilities affecting your project's dependencies.

➡️ Provides an officially supported frontend to the OSV database that connects a project’s list of dependencies with the vulnerabilities that affect them.

➡️ Each advisory comes from an open and authoritative source (e.g. the RustSec Advisory Database)

➡️ Anyone can suggest improvements to advisories, resulting in a very high quality database

➡️ The OSV format unambiguously stores information about affected versions in a machine-readable format that precisely maps onto a developer’s list of packages

Repo:
github.com/google/osv-scanner

Blog:
security.googleblog.com/2022/1

Site:
osv.dev//#use-the-cli

#golang #infosec #websecurity #osv #osvscanner #devsecops

Last updated 2 years ago