Google ืคึผืึทื‘ืœื™ืฉืึทื– OSV-Scanner, ืึท ื“ืขืคึผืขื ื“ืขื ืกื™-ืึทื•ื•ืขืจ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืกืงืึทื ื ืขืจ

Google ื”ืึธื˜ ื‘ืึทืงืขื ืขื  ื“ื™ OSV-Scanner ื˜ืึธืึธืœืงื™ื˜ ืฆื• ืงืึธื ื˜ืจืึธืœื™ืจืŸ ืคึฟืึทืจ ืึทื ืคึผืึทื˜ืฉื˜ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ ืงืึธื“ ืื•ืŸ ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื–, ื’ืขื ื•ืžืขืŸ ืื™ืŸ ื—ืฉื‘ื•ืŸ ื“ื™ ื’ืื ืฆืข ืงื™ื™ื˜ ืคื•ืŸ ื“ื™ืคึผืขื ื“ืึทื ืกื™ื– ืคืืจื‘ื•ื ื“ืŸ ืžื™ื˜ ื“ื™ ืงืึธื“. OSV-Scanner ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื™ื“ืขื ื˜ื™ืคื™ืฆื™ืจืŸ ืกื™ื˜ื•ืึทื˜ื™ืึธื ืก ื•ื•ื• ืึท ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ ื•ื•ืขืจื˜ ืฉืคึผื™ืจืขื•ื•ื“ื™ืง ืจืขื›ื˜ ืฆื• ืคึผืจืึธื‘ืœืขืžืก ืื™ืŸ ืื™ื™ื ืขืจ ืคื•ืŸ ื“ื™ ืœื™ื™ื‘ืจืขืจื™ื– ื’ืขื ื™ืฆื˜ ื•ื•ื™ ืึท ื“ืขืคึผืขื ื“ืขื ืกื™. ืื™ืŸ ื“ืขื ืคืึทืœ, ื“ื™ ืฉืคึผื™ืจืขื•ื•ื“ื™ืง ื‘ื™ื‘ืœื™ืึธื˜ืขืง ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ืžื™ื ืึทืฆืึทื“, ื“.ื”. ื•ื•ืขืจืŸ ื’ืขืจื•ืคืŸ ื“ื•ืจืš ืืŸ ืื ื“ืขืจ ื“ืขืคึผืขื ื“ืขื ืกื™. ื“ื™ ืคึผืจื•ื™ืขืงื˜ ืงืึธื“ ืื™ื– ื’ืขืฉืจื™ื‘ืŸ ืื™ืŸ Go ืื•ืŸ ืคื•ื ืื ื“ืขืจื’ืขื˜ื™ื™ืœื˜ ืื•ื ื˜ืขืจ ื“ื™ Apache 2.0 ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ.

OSV-Scanner ืงืขื ืขืŸ ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ ืจืขืงื•ืจืกื™ื•ื•ืœื™ ื™ื‘ืขืจืงื•ืงืŸ ืึท ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ ื‘ื•ื™ื, ื™ื“ืขื ื˜ื™ืคื™ืฆื™ืจืŸ ืคึผืจืึทื“ื–ืฉืขืงืก ืื•ืŸ ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื– ื“ื•ืจืš ื“ื™ ื‘ื™ื™ึทื–ื™ื™ึทืŸ ืคื•ืŸ ื’ื™ื˜ ื“ื™ื™ืจืขืงื˜ืขืจื™ื– (ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ื– ื‘ืืฉืœืืกืŸ ื“ื•ืจืš ืึทื ืึทืœื™ืกื™ืก ืคื•ืŸ ื™ื‘ืขืจื’ืขื‘ืŸ ื”ืึทืฉืขืก), SBOM ื˜ืขืงืขืก (Software Bill Of Material ืื™ืŸ SPDX ืื•ืŸ CycloneDX ืคึฟืึธืจืžืึทื˜ื™ืจื•ื ื’ืขืŸ), ืžืึทื ืึทืคืขืกื˜ื™ื– ืึธื“ืขืจ ืฉืœืึธืก ื˜ืขืงืข ืžืึทื ืึทื“ื–ืฉืขืจื– ืึทื–ืึท ื•ื•ื™ Yarn, NPM, GEM, PIP ืื•ืŸ Cargo. ืขืก ืื•ื™ืš ืฉื˜ื™ืฆื˜ ืกืงืึทื ื™ื ื’ ื“ื™ ืื™ื ื”ืึทืœื˜ ืคื•ืŸ ื“ืึธืงืงืขืจ ืงืึทื ื˜ื™ื™ื ืขืจ ื‘ื™ืœื“ืขืจ ื’ืขื‘ื•ื™ื˜ ืคึฟื•ืŸ ืคึผืึทืงืึทื“ื–ืฉืึทื– ืคื•ืŸ ื“ืขื‘ื™ืึทืŸ ืจื™ืคึผืึทื–ืึทื˜ืึธืจื™ื–.

Google ืคึผืึทื‘ืœื™ืฉืึทื– OSV-Scanner, ืึท ื“ืขืคึผืขื ื“ืขื ืกื™-ืึทื•ื•ืขืจ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืกืงืึทื ื ืขืจ

ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ื– ื’ืขื ื•ืžืขืŸ ืคึฟื•ืŸ ื“ื™ OSV (Open Source Vulnerabilities) ื“ืึทื˜ืึทื‘ื™ื™ืก, ื•ื•ืึธืก ืงืึธื•ื•ืขืจืก ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืคึผืจืึธื‘ืœืขืžืก ืื™ืŸ ื“ื™ Crates.io (Rust), Go, Maven, NPM (JavaScript), NuGet (C #), Packagist (PHP), PyPI. (Python), RubyGems, Android, Debian ืื•ืŸ Alpine, ื•ื•ื™ ื’ืขื–ื•ื ื˜ ื•ื•ื™ ื“ืึทื˜ืŸ ื•ื•ืขื’ืŸ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ ื“ื™ ืœื™ื ื•ืงืก ืงืขืจืŸ ืื•ืŸ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืคึฟื•ืŸ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืจื™ืคึผืึธืจืฅ ืื™ืŸ ืคึผืจืึทื“ื–ืฉืขืงืก ื›ืึธื•ืกื˜ื™ื“ ืื•ื™ืฃ GitHub. ื“ื™ OSV ื“ืึทื˜ืึทื‘ื™ื™ืก ืจื™ืคืœืขืงืก ื“ื™ ืกื˜ืึทื˜ื•ืก ืคื•ืŸ ื“ื™ ืคึผืจืึธื‘ืœืขื ืคืึทืจืจื™ื›ื˜ืŸ, ื™ื ื“ื™ืงื™ื™ืฅ ื“ื™ ืงืึทืžื™ืฅ ืžื™ื˜ ื“ื™ ืื•ื™ืกื–ืขืŸ ืื•ืŸ ืงืขืจืขืงืฉืึทืŸ ืคื•ืŸ ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™, ื“ื™ ืงื™ื™ื˜ ืคื•ืŸ ื•ื•ืขืจืกื™ืขืก ืึทืคืขืงื˜ืึทื“ ื“ื•ืจืš ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™, ืคึฟืึทืจื‘ื™ื ื“ื•ื ื’ืขืŸ ืฆื• ื“ื™ ืคึผืจื•ื™ืขืงื˜ ืจื™ืคึผืึทื–ืึทื˜ืึธืจื™ ืžื™ื˜ ื“ื™ ืงืึธื“ ืื•ืŸ ืึท ืึธื ื–ืึธื’ ื•ื•ืขื’ืŸ ื“ืขื ืคึผืจืึธื‘ืœืขื. ื“ื™ ืฆื•ื’ืขืฉื˜ืขืœื˜ API ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืฉืคึผื•ืจ ื“ื™ ืžืึทื ืึทืคืขืกื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื•ื™ืฃ ื“ื™ ืžื“ืจื’ื” ืคื•ืŸ ืงืึทืžื™ืฅ ืื•ืŸ ื˜ืึทื’ืก ืื•ืŸ ืึทื ืึทืœื™ื™ื– ื“ื™ ืกืึทืกืขืคึผื˜ืึทื‘ื™ืœืึทื˜ื™ ืคื•ืŸ ื“ืขืจื™ื•ื•ืึทื˜ ืคึผืจืึธื“ื•ืงื˜ืŸ ืื•ืŸ ื“ื™ืคึผืขื ื“ืึทื ืกื™ื– ืฆื• ื“ืขื ืคึผืจืึธื‘ืœืขื.

Google ืคึผืึทื‘ืœื™ืฉืึทื– OSV-Scanner, ืึท ื“ืขืคึผืขื ื“ืขื ืกื™-ืึทื•ื•ืขืจ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืกืงืึทื ื ืขืจ


ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’