osv-scanner VS maloss

Compare osv-scanner vs maloss and see what are their differences.

osv-scanner

Vulnerability scanner written in Go which uses the data provided by https://osv.dev (by google)

maloss

Towards Measuring Supply Chain Attacks on Package Managers for Interpreted Languages (by osssanitizer)
InfluxDB - Power Real-Time Data Analytics at Scale
Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.
www.influxdata.com
featured
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com
featured
osv-scanner maloss
10 3
5,856 106
1.5% -
9.6 0.0
7 days ago over 1 year ago
Go Java
Apache License 2.0 MIT License
The number of mentions indicates the total number of mentions that we've tracked plus the number of user suggested alternatives.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.

osv-scanner

Posts with mentions or reviews of osv-scanner. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2023-04-25.

maloss

Posts with mentions or reviews of maloss. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2022-12-16.

What are some alternatives?

When comparing osv-scanner and maloss you can also consider the following projects:

trivy - Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

packj - Packj stops :zap: Solarwinds-, ESLint-, and PyTorch-like attacks by flagging malicious/vulnerable open-source dependencies ("weak links") in your software supply-chain

betterscan-ce - Code Scanning/SAST/Static Analysis/Linting using many tools/Scanners + OpenAI GPT with One Report (Code, IaC) - Betterscan Community Edition (CE)

pypi_malware - PyPI malware packages

osv.dev - Open source vulnerability DB and triage service.

melange - build APKs from source code

apko - Build OCI images from APK packages directly without Dockerfile

software-supply-chain-compromises - A dataset of software supply chain compromises. Please help us maintain it!