ื’ื•ื’ืœ ืžืคืจืกืžืช ืืช OSV-Scanner, ืกื•ืจืง ืคื’ื™ืขื•ืช ืžื•ื“ืข ืœืชืœื•ืช

ื’ื•ื’ืœ ื”ืฆื™ื’ื” ืืช ืขืจื›ืช ื”ื›ืœื™ื OSV-Scanner ืœื‘ื“ื™ืงืช ืคื’ื™ืขื•ื™ื•ืช ืฉื˜ืจื ืชื•ืงื ื• ื‘ืงื•ื“ ื•ื‘ืืคืœื™ืงืฆื™ื•ืช, ืชื•ืš ื”ืชื—ืฉื‘ื•ืช ื‘ื›ืœ ืฉืจืฉืจืช ื”ืชืœื•ืช ื”ืงืฉื•ืจื” ืœืงื•ื“. OSV-Scanner ืžืืคืฉืจ ืœื–ื”ื•ืช ืžืฆื‘ื™ื ืฉื‘ื”ื ืืคืœื™ืงืฆื™ื” ื”ื•ืคื›ืช ืœืคื’ื™ืขื” ืขืงื‘ ื‘ืขื™ื•ืช ื‘ืื—ืช ืžื”ืกืคืจื™ื•ืช ื”ืžืฉืžืฉื•ืช ื›ืชืœื•ืช. ื‘ืžืงืจื” ื–ื”, ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ืกืคืจื™ื™ื” ื”ืคื’ื™ืขื” ื‘ืขืงื™ืคื™ืŸ, ื›ืœื•ืžืจ. ืœื”ื™ืงืจื ื“ืจืš ืชืœื•ืช ืื—ืจืช. ืงื•ื“ ื”ืคืจื•ื™ืงื˜ ื›ืชื•ื‘ ื‘-Go ื•ืžื•ืคืฅ ืชื—ืช ืจื™ืฉื™ื•ืŸ Apache 2.0.

OSV-Scanner ื™ื›ื•ืœ ืœืกืจื•ืง ื‘ืื•ืคืŸ ืื•ื˜ื•ืžื˜ื™ ืจืงื•ืจืกื™ื‘ื™ืช ืขืฅ ืกืคืจื™ื•ืช, ืœื–ื”ื•ืช ืคืจื•ื™ืงื˜ื™ื ื•ื™ื™ืฉื•ืžื™ื ืขืœ ื™ื“ื™ ื ื•ื›ื—ื•ืช ืฉืœ ืกืคืจื™ื•ืช git (ืžื™ื“ืข ืขืœ ืคื’ื™ืขื•ื™ื•ืช ื ืงื‘ืข ื‘ืืžืฆืขื•ืช ื ื™ืชื•ื— ืฉืœ commit hashes), ืงื‘ืฆื™ SBOM (Software Bill Of Material ื‘ืคื•ืจืžื˜ื™ื SPDX ื•-CycloneDX), ืžื ื™ืคืกื˜ื™ื ืื• ืžื ื”ืœื™ ื—ื‘ื™ืœื•ืช ืœื ืขื•ืœ ืงื‘ืฆื™ื ื›ื’ื•ืŸ Yarn, NPM, GEM, PIP ื•-Cargo. ื–ื” ื’ื ืชื•ืžืš ื‘ืกืจื™ืงืช ื”ืชื•ื›ืŸ ืฉืœ ืชืžื•ื ื•ืช ืžื™ื›ืœ Docker ืฉื ื‘ื ื• ืžื—ื‘ื™ืœื•ืช ืžืžืื’ืจื™ ื“ื‘ื™ืืŸ.

ื’ื•ื’ืœ ืžืคืจืกืžืช ืืช OSV-Scanner, ืกื•ืจืง ืคื’ื™ืขื•ืช ืžื•ื“ืข ืœืชืœื•ืช

ืžื™ื“ืข ืขืœ ืคื’ื™ืขื•ื™ื•ืช ื ืœืงื— ืžืžืกื“ ื”ื ืชื•ื ื™ื OSV (Open Source Vulnerabilities), ื”ืžื›ืกื” ืžื™ื“ืข ืขืœ ื‘ืขื™ื•ืช ืื‘ื˜ื—ื” ื‘-Crates.io (Rust), Go, Maven, NPM (JavaScript), NuGet (C#), Packagist (PHP), PyPI (Python), RubyGems, Android, Debian ื•-Alpine, ื›ืžื• ื’ื ื ืชื•ื ื™ื ืขืœ ืคืจืฆื•ืช ื‘ืœื™ื‘ืช ืœื™ื ื•ืงืก ื•ืžื™ื“ืข ืžื“ื•ื—ื•ืช ืคื’ื™ืขื•ืช ื‘ืคืจื•ื™ืงื˜ื™ื ื”ืžืชืืจื—ื™ื ื‘-GitHub. ืžืกื“ ื”ื ืชื•ื ื™ื ืฉืœ ื”-OSV ืžืฉืงืฃ ืืช ืžืฆื‘ ืชื™ืงื•ืŸ ื”ื‘ืขื™ื”, ืžืฆื™ื™ืŸ ืืช ื”ื”ืชื—ื™ื™ื‘ื•ื™ื•ืช ืขื ื”ื•ืคืขืชื” ื•ืชื™ืงื•ืŸ ื”ืคื’ื™ืขื•ืช, ืžื’ื•ื•ืŸ ื”ื’ืจืกืื•ืช ื”ืžื•ืฉืคืขื•ืช ืžื”ืคื’ื™ืขื•ืช, ืงื™ืฉื•ืจื™ื ืœืžืื’ืจ ื”ืคืจื•ื™ืงื˜ ืขื ื”ืงื•ื“ ื•ื”ื•ื“ืขื” ืขืœ ื”ื‘ืขื™ื”. ื”-API ื”ืžืกื•ืคืง ืžืืคืฉืจ ืœืš ืœืขืงื•ื‘ ืื—ืจ ื‘ื™ื˜ื•ื™ ืฉืœ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘ืจืžืช ื”-commits ื•ื”ืชื’ื™ื ื•ืœื ืชื— ืืช ื”ืจื’ื™ืฉื•ืช ืฉืœ ืžื•ืฆืจื™ื ื ื’ื–ืจื™ื ื•ืชืœื•ืช ืœื‘ืขื™ื”.

ื’ื•ื’ืœ ืžืคืจืกืžืช ืืช OSV-Scanner, ืกื•ืจืง ืคื’ื™ืขื•ืช ืžื•ื“ืข ืœืชืœื•ืช


ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”