nancy
vulndb
Our great sponsors
nancy | vulndb | |
---|---|---|
2 | 3 | |
543 | 538 | |
0.9% | 0.6% | |
5.5 | 9.7 | |
10 days ago | 2 days ago | |
Go | Go | |
Apache License 2.0 | GNU General Public License v3.0 or later |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
nancy
-
Open-source way to scan dependencies for CVEs?
Please, check https://github.com/sonatype-nexus-community/nancy
-
What is the equivalent of "npm audit" in go?
Nancy checks for vunerabilities using public vulnerabilities database. It can also check using sonatype private db, but for that you'd have to pay.
vulndb
-
GitHub brings supply chain security features to the Go community
With "Go vulnerability database", do you mean https://github.com/golang/vulndb?
-
What is the equivalent of "npm audit" in go?
An official vulnerability database for exactly that is in the making: https://go.googlesource.com/proposal/+/master/design/draft-vulndb.md https://github.com/golang/vulndb
-
Google's unified vulnerability schema for open source supports Rust on launch
Today, we’re excited to announce a new milestone in expanding OSV to several key open-source ecosystems: Go, Rust, Python, and DWF.
What are some alternatives?
Gitea - Git with a cup of tea! Painless self-hosted all-in-one software development service, including Git hosting, code review, team collaboration, package registry and CI/CD
rustsec - RustSec API & Tooling
cli - GitHub’s official command line tool
advisory-db - Security advisory database for Rust crates published through crates.io
prometheus - The Prometheus monitoring system and time series database.
advisory-database - Advisory database for Python packages published on pypi.org
pip-audit - Audits Python environments, requirements files and dependency trees for known security vulnerabilities, and can automatically fix them
advisory-db - Security advisory database for Rust crates published through crates.io
go-formatter - A curated list of awesome Go frameworks, libraries and software
advisory-database - Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Hugo - The world’s fastest framework for building websites.
dwflist - The DWF IDs