A vulnerability scanner for container images and filesystems
-
Updated
Aug 21, 2026 - Go
A vulnerability scanner for container images and filesystems
Pure-Rust Android decompiler and security-audit suite. DEX → Java, Hermes → JavaScript. Cross-layer taint across the React Native bridge. CycloneDX SBOM + OpenVEX. CLI and MCP. Bytecode is not a security layer.
Guided VEX authoring for OSS maintainers — from zero to a published VEX document in one command.
Deterministic, reachability-aware software composition analysis (SCA) engine — lockfile-first resolution, function- & cross-package reachability, patch-diff symbol mining, EPSS/KEV, SARIF + OpenVEX. Zero runtime dependencies.
CA9 is a local evidence engine for Python AppSec triage. It sits after scanners and before engineers waste time, proving which findings matter.
SBOM diff with supply-chain risk signals — flags new CVEs, typosquats, and young maintainers on changed deps. Built after axios (Mar 2026), Shai-Hulud, and xz.
APK / AAB / XAPK parser and security analysis library. Signing v1–v4 + ROCA / Fermat / Wiener / batch-GCD. CycloneDX SBOM with .rodata byte anchors. OpenVEX. YARA-X. Pure Rust.
VEX document crawler and aggregator
Ultra-fast open-source code security scanner. Finds vulnerabilities across 8 languages (Rust, Go, Python, JS, TS, Java, C, C++) using SAST + taint analysis + LLM verification — fewer false positives, faster audits. Outputs Sigstore-signed SARIF, SBOM, and OpenVEX bundles for supply-chain compliance.
The EU Cyber Resilience Act chain, end to end and offline: SBOM, VEX, vulnerability scan, Article 14 reporting, signed updates, and an Annex VII pack that prints its own gaps first. Awareness cannot be backdated once anything is filed, and a dismissal cannot remove a legal deadline.
VEX statements for SUSE Observability product images. Consumable by Trivy via --vex repo.
Universal SLSA evidence engine and verifier — and the release engine that produces the evidence: versions, changelogs, SBOMs, VEX, attestations, and the walk a stranger runs to check them
FDA-ready SBOM, vulnerability scan, and VEX triage pipeline for medical-device software (§524B)
Local pack gates for CRA readiness — humans review. Not conformity assessment.
Add a description, image, and links to the openvex topic page so that developers can more easily learn about it.
To associate your repository with the openvex topic, visit your repo's landing page and select "manage topics."