ossf/cve-bin-tool
The CVE Binary Tool helps you determine if your system includes known vulnerabilities. You can scan binaries for over 350 common, vulnerable components (openssl, libpng, libxml2, expat and others), or if you know the components used, you can get a list of known vulnerabilities associated with an SBOM or a list of components and versions.
cve-bin-tool.readthedocs.io/en/latest ↗github.com/ossf/cve-bin-tool ↗
Only 11 of the 39 people who sent their first pull request here got it merged.
16 of 58outside PRs merged (28%)
checked
Where newcomer work lands
The evidence