Open-source way to scan dependencies for CVEs?

This page summarizes the projects mentioned and recommended in the original post on /r/golang

InfluxDB - Power Real-Time Data Analytics at Scale
Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
  • pip-audit

    Audits Python environments, requirements files and dependency trees for known security vulnerabilities, and can automatically fix them

    Something like python's pip-audit. For commercial solutions I know there's Snyk and Jfrog we can always purchase, but I'm interested to see if there's an open-source tool that can do this.

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
  • nancy

    A tool to check for vulnerabilities in your Golang dependencies, powered by Sonatype OSS Index (by sonatype-nexus-community)

    Please, check

NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts

  • Show HN: One makefile to rule them all

    3 projects | | 19 Oct 2023
  • pip-audit - a tool for scanning Python environments for packages with known vulnerabilities

    1 project | /r/bag_o_news | 5 Dec 2021
  • Find malicious Python packages with one command

    1 project | | 4 Dec 2021
  • pip-audit: a tool for identifying Python packages with known vulnerabilities

    1 project | /r/pythoncoding | 1 Dec 2021
  • A tool for scanning Python environments for known vulnerabilities

    1 project | /r/CKsTechNews | 1 Dec 2021

Did you konow that Go is
the 4th most popular programming language
based on number of metions?