OpenSCA is participating 2021 OSC China Open Source Project Selection , please vote for it!
OpenSCA in 2021 OSC China Open Source Project Selection {{projectVoteCount} has been obtained in, please vote for it!
2021 OSC China Open Source Project Selection It is in hot progress. Come and vote for your favorite open source project!
2021 OSC China Open Source Project Selection>>> Midfield Review
OpenSCA won the 2021 OSC China Open Source Project Award "The Best Popularity Project" !
Authorization Agreement Apache
development language Google Go
operating system Cross platform
Software type Open source software
Open source organizations nothing
region domestic
deliverer OpenSCA
intended for unknown
Recording time 2022-04-12

Software Introduction

OpenSCA is an open source software component analysis tool, which is used to scan third-party component dependency and vulnerability information of projects.

As the open source version of the OSS open-source threat control product (opens new window) of Hanging Mirror Security, OpenSCA inherits the core capabilities of OSS, such as security defect detection of multi-source SCA open source applications. Through software composition analysis, dependency analysis, feature analysis, reference identification, compliance analysis and other methods, it deeply explores various security vulnerabilities and open source protocol risks hidden in components to ensure the security of application open source component introduction.

Application scenarios

Security Development

  • OpenSCA open source IDE open source risk detection plug-in helps individual/enterprise developers quickly locate and repair vulnerabilities
  • Friendly developers, lightweight and low-cost zero threshold installation
  • Enterprise level SCA core engine, supporting secondary development

Safety test

  • Security testing of third-party open source components of products
  • Improve the security of software products and prevent applications from going online with problems

security management

  • Security access of third-party components and supplier software
  • Establishment of enterprise internal security component library
  • Sort out the visual list of software or component assets
  • Security department compliance review and related open source governance
Expand to read the full text

code

Gitee index of is
exceed Items for

comment

Click to lead the topic 📣 Post and join the discussion 🔥
Published information
2022/07/01 15:41

OpenSCA v1.0.7 was officially released, with new Python language support

On June 29, 2022, the new version of OpenSCA v1.0.7 will be officially released, and the blockbuster functions will be continuously updated to meet more user needs. 1. The v1.0.7 update adds open source component detection that supports Python. The static parsing of the new Gradle package management tool optimizes the display effect of the same component when checked out in different paths. 2 Update description (1) New open source component detection that supports Python. In this version, we add an important function that supports open source component detection of the pipfile, pipfile.lock, and setup.py feature files of the Python language pip package management tool. (2)...

zero
three
Published information
2022/04/21 17:51

Version upgrade | Hanging mirror security OpenSCA v1.0.5

The introduction invites you to explore this, and the version is updated. Through the efforts of R&D and product partners day and night, OpenSCA version 1.0.5 was successfully released! This version updates the language detection, let's take a look! The v1.0.5 update adds the detection method of the Ebar.lock file of the Erlang language Rebar package manager. Visit the OpenSCA open source project and download the latest version of OpenSCA: https://gitee.com/XmirrorSecurity/OpenSCA-cli/ Detection capability ps: purple font is a new part~Support the language pack manager to parse the file Java Maven pom.xml JavaScr

two
one
Published information
2022/04/12 16:42

Version upgrade | OpenSCA v1.0.3 release

The introduction comes out after a thousand calls, and the version is upgraded! In the expectation of all, OpenSCA v1.0.3 has finally hatched and released successfully! Through the efforts of R&D and product partners day and night, this version has updated the language detection and file parsing. Let's have a look! V1.0.3 Updates Detection of the newly added JavaScript language npm package manager yarn.lock New PHP language composer dependency management tool composer. json detection New Ruby language gem package manager gems.locked detection

zero
one
No more
Loading failed, please refresh the page
Click to load more
Loading
next page
{{o.pubDate | formatDate}}

{{formatAllHtml(o.title)}}

{{parseInt(o.replyCount) | bigNumberTransform}}
{{parseInt(o.viewCount) | bigNumberTransform}}
No more
No content temporarily
Issued a question and answer
{{o.pubDate | formatDate}}

{{formatAllHtml(o.title)}}

{{parseInt(o.replyCount) | bigNumberTransform}}
{{parseInt(o.viewCount) | bigNumberTransform}}
No more
No content temporarily
No content temporarily
zero comment
forty-three Collection
 OSCHINA
Log in to view more high-quality content
 Back to top
Top