Saturday, June 28, 2025
Google search engine
HomeTechnologyCyber SecurityVulnerability scanner and remediation instrument for open supply

Vulnerability scanner and remediation instrument for open supply


In December 2022, we launched the open supply OSV-Scanner instrument, and earlier this 12 months, we open sourced OSV-SCALIBR. OSV-Scanner and OSV-SCALIBR, along with OSV.dev are elements of an open platform for managing vulnerability metadata and enabling easy and correct matching and remediation of recognized vulnerabilities. Our purpose is to simplify and streamline vulnerability administration for builders and safety groups alike.

At the moment, we’re thrilled to announce the launch of OSV-Scanner V2.0.0, following the announcement of the beta model. This V2 launch builds upon the inspiration we laid with OSV-SCALIBR and provides important new capabilities to OSV-Scanner, making it a complete vulnerability scanner and remediation instrument with broad assist for codecs and ecosystems.

What’s new

Enhanced Dependency Extraction with OSV-SCALIBR

This launch represents the primary main integration of OSV-SCALIBR options into OSV-Scanner, which is now the official command-line code and container scanning instrument for the OSV-SCALIBR library. This integration additionally expanded our assist for the sorts of dependencies we will extract from initiatives and containers:

Supply manifests and lockfiles:

Artifacts:

Node modules

Python wheels

Java uber jars

Go binaries

Layer and base image-aware container scanning

Beforehand, OSV-Scanner centered on scanning of supply repositories and language package deal manifests and lockfiles. OSV-Scanner V2 provides assist for complete, layer-aware scanning for Debian, Ubuntu, and Alpine container pictures. OSV-Scanner can now analyze container pictures to offer:

Layers the place a package deal was first launched

Layer historical past and instructions

Base pictures the picture relies on (leveraging a new experimental API offered by deps.dev).

OS/Distro the container is operating on

Filtering of vulnerabilities which can be unlikely to affect your container picture

This layer evaluation at present helps the next OSes and languages:

Distro Help:

Language Artifacts Help:

Interactive HTML output

Presenting vulnerability scan data in a transparent and actionable manner is tough, notably within the context of container scanning. To deal with this, we constructed a brand new interactive native HTML output format. This supplies extra interactivity and data in comparison with terminal solely outputs, together with:

And moreover for container picture scanning:

Illustration of HTML output for container picture scanning

Guided remediation for Maven pom.xml

Final 12 months we launched a function referred to as guided remediation for npmwhich streamlines vulnerability administration by intelligently suggesting prioritized, focused upgrades and providing versatile methods. This finally maximizes safety enhancements whereas minimizing disruption. Now we have now expanded this function to Java by way of assist for Maven pom.xml.

With guided remediation assist for Maven, you’ll be able to remediate vulnerabilities in each direct and transitive dependencies by way of direct model updates or overriding variations by way of dependency administration.

We’ve launched a couple of new issues for our Maven assist:

A brand new remediation technique override.

Help for studying and writing pom.xml information, together with writing adjustments to native mother or father pom information. We leverage OSV-Scalibr for Maven transitive dependency extraction.

A personal registry will be specified to fetch Maven metadata.

A brand new experimental subcommend to replace all of your dependencies in pom.xml to the most recent model.

We additionally launched machine readable output for guided remediation that makes it simpler to combine guided remediation into your workflow.

What’s subsequent?

Now we have thrilling plans for the rest of the 12 months, together with:

Continued OSV-SCALIBR Convergence: We are going to proceed to converge OSV-Scanner and OSV-SCALIBR to convey OSV-SCALIBR’s performance to OSV-Scanner’s CLI interface.

Expanded Ecosystem Help: We’ll develop the variety of ecosystems we assist throughout all of the options at present in OSV-Scanner, together with extra languages for guided remediation, OS advisories for container scanning, and extra normal lockfile assist for supply code scanning.

Full Filesystem Accountability for Containers: One other purpose of osv-scanner is to provide the capacity to know and account for each single file in your container picture, together with sideloaded binaries downloaded from the web.

Reachability Evaluation: We’re engaged on integrating reachability evaluation to offer deeper insights into the potential affect of vulnerabilities.

VEX Help: We’re planning so as to add assist for Vulnerability Change (VEX) to facilitate higher communication and collaboration round vulnerability data.

Strive and so forth scanner V2

You’ll be able to strive V2.0.0 and contribute to its ongoing improvement by trying out And so on scanner or the OSV-SCALIBR repository. We welcome your suggestions and contributions as we proceed to enhance the platform and make vulnerability administration simpler for everybody.

You probably have any questions or if you need to contribute, do not hesitate to succeed in out to us at osv-discuss@google.com, or put up a problem in our concern tracker.



Supply hyperlink

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -
Google search engine

Most Popular

Recent Comments