Our great sponsors
-
log4jscanner
Discontinued A log4j vulnerability filesystem scanner and Go package for analyzing JAR files.
-
InfluxDB
Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.
As written before, there is grype you can integrate it into your Jenkins build and it will catch many different things. When checking for Log4J we found out that we were not vulnerable to that but we were using a Docker Image that had many other vulnerabilites, so we adapted our build and used a simpler one.
NOTE:
The number of mentions on this list indicates mentions on common posts plus user suggested alternatives.
Hence, a higher number means a more popular project.