- entendu parler ?
- utilisé ?
- utilise ?
##Pourquoi ?
âComponent Analysis platform that allows organizations to identify and reduce risk in the software supply chainâ
-
Analyse / correction en continu des alertes de vulnĂ©rabilitĂ©s : dĂ©tection, analyse de lâimpact, priorisation, correction, suivi
-
Gestion des licences
- Rust
- Composer (PHP)
- Gems (Ruby)
- Hex (Erlang/Elixir)
- Maven (Java)
- NPM (Javascript)
- NuGet (.NET)
- Pypi (Python)
- National Vulnerability Database: https://nvd.nist.gov đșđž
- GitHub Advisory: https://github.com/advisories) đ
- Open Source Vulnerabilities: https://osv.dev/list đ§âđ»
- Snyk, Sonatype, VulnDB etc.
A Vidal, merci Jean-Christophe !
- pouvoir exporter un rapport dâaudit (format VEX ?)
- avoir un joli rapport dâaudit
- automatiser lâimport des composants (SBOM)