CVEの各種データを収集、バイナリをスキャンしたりSBOMやパッケージをチェックしてトリアージを行いレポートを生成するまでを支援するツール。元はIntelで開発されたツールらしい。
---
GitHub - ossf/cve-bin-tool: The CVE Binary Tool helps you determine if your system includes known vulnerabilities. You can scan binaries for over 350 common, vulnerable components (openssl, libpng, libxml2, expat and others), or if you know the components
https://github.com/ossf/cve-bin-tool
#bookmarks