awesome-repositories.com
Blog
MCP
awesome-repositories.com

Entdecke die besten Open-Source-Repositories mit KI-gestützter Suche.

EntdeckenKuratierte SuchenOpen-Source-AlternativenSelf-hosted SoftwareBlogSitemap
ProjektMCP-ServerÜber unsRanking-MethodikPresse
RechtlichesDatenschutzAGB
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

Scanner für Abhängigkeitsschwachstellen

Ranking aktualisiert am 30. Juni 2026

For Scanner für Abhängigkeits-Schwachstellen, the strongest matches are future-architect/vuls (Vuls scans lockfiles for vulnerable dependencies and cross-references them), google/osv-scanner (osv-scanner is a comprehensive lockfile vulnerability scanner that uses) and aquasecurity/trivy (Trivy scans lockfiles from many ecosystems against its own). snyk/snyk and dependabot/dependabot-core round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.

Automatisierte Tools, die Sicherheitslücken in Lockfiles und Abhängigkeitsmanifesten von Projekten identifizieren und melden.

Scanner für Abhängigkeitsschwachstellen

Finde die besten Repos mit KI.Wir suchen mit KI nach den am besten passenden Repositories.
  • future-architect/vulsAvatar von future-architect

    future-architect/vuls

    12,185Auf GitHub ansehen↗

    Vuls is an agentless vulnerability scanner and CVE intelligence aggregator. It identifies security flaws in operating systems, containers, and network devices without requiring the installation of permanent software agents on target machines. The project distinguishes itself by cross-referencing software versions against multiple vulnerability databases, security advisories, and known exploit catalogs. It utilizes platform-based enumeration and lockfile analysis to detect vulnerabilities in network hardware, programming libraries, and website plugins. The tool covers a broad range of securit

    Vuls scans lockfiles for vulnerable dependencies and cross-references them against multiple CVE databases, making it a capable dependency scanner, though its primary focus on OS and network devices means it is a broader vulnerability scanner rather than a lockfile-only tool.

    GoVulnerability DatabasesDependency AuditingVulnerability Intelligence Feeds
    Auf GitHub ansehen↗12,185
  • google/osv-scannerAvatar von google

    google/osv-scanner

    10,565Auf GitHub ansehen↗

    osv-scanner is a software composition analysis tool and vulnerability scanner that checks project dependencies and container images against the Open Source Vulnerabilities database. It functions as a dependency remediation tool and can be integrated into custom Go applications as a programmable security library. The project distinguishes itself through a remediation workflow that includes an interactive terminal user interface and automated scripting for upgrading vulnerable packages in lockfiles and manifests. It employs call-graph reachability analysis to determine if vulnerable code is act

    osv-scanner is a comprehensive lockfile vulnerability scanner that uses the OSV database to detect and remediate vulnerable dependencies across multiple languages, with a CLI, automated remediation workflows, and CI/CD integration capabilities.

    GoCommand Line Interfaces
    Auf GitHub ansehen↗10,565
  • aquasecurity/trivyAvatar von aquasecurity

    aquasecurity/trivy

    36,462Auf GitHub ansehen↗

    Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container images, filesystems, and infrastructure as code files. It functions as a software composition analysis tool and an infrastructure security scanner, providing automated checks for CI/CD pipelines and cloud environments to ensure the integrity of the software supply chain. The tool distinguishes itself through a modular, plugin-based architecture that allows for the independent inspection of diverse targets. It utilizes a declarative policy engine to evaluate configurations agai

    Trivy scans lockfiles from many ecosystems against its own vulnerability database, provides severity ratings and remediation suggestions, and integrates directly into CI/CD pipelines, making it a complete lockfile vulnerability scanner.

    GoVulnerability Intelligence Feeds
    Auf GitHub ansehen↗36,462
  • snyk/snykAvatar von snyk

    snyk/snyk

    5,586Auf GitHub ansehen↗

    Snyk is an application security testing platform designed to identify and remediate vulnerabilities across source code, open-source dependencies, container images, and infrastructure-as-code configurations. It functions as a comprehensive security workflow automation tool, utilizing a static analysis engine and dependency graph mapping to detect security flaws and license compliance issues throughout the software development lifecycle. The platform distinguishes itself through agentic workflow orchestration and an automated remediation pipeline that generates and submits pull requests to patc

    Snyk is a developer security platform that scans project lockfiles for known vulnerabilities, provides severity reports and remediation suggestions, and works from the command line and CI/CD pipelines across many languages, making it a comprehensive fit for this search.

    TypeScriptApplication Security Testing PlatformsDependency Vulnerability ScanningSecurity Vulnerability Scanning
    Auf GitHub ansehen↗5,586
  • dependabot/dependabot-coreAvatar von dependabot

    dependabot/dependabot-core

    5,413Auf GitHub ansehen↗

    dependabot-core is the automated dependency management engine that powers multi-ecosystem package updates and vulnerability remediation. It parses package manifests and lockfiles, polls package registries for newer versions, resolves version constraints across entire dependency trees, and generates pull requests with changelogs and structured descriptions. The system integrates vulnerability database matching to detect known security flaws and can automatically create remediation pull requests. What distinguishes this project is its handling of complex multi-ecosystem resolution across dozens

    dependabot-core parses project lockfiles across dozens of ecosystems, matches dependencies against a vulnerability database, and generates automated remediation pull requests, covering lockfile scanning, severity reporting, and CI/CD integration out of the box.

    RubyAutomated Dependency UpdatersAutomated Update Pull RequestsCredential Injection Proxies
    Auf GitHub ansehen↗5,413
  • dependencytrack/dependency-trackAvatar von DependencyTrack

    DependencyTrack/dependency-track

    3,612Auf GitHub ansehen↗

    Dependency-Track is a software composition analysis tool and vulnerability management system designed to track dependencies and supply chain risk. It functions as a platform for ingesting and analyzing CycloneDX software bills of materials to identify known vulnerabilities and license compliance issues within third-party software components. The system distinguishes itself by mirroring external vulnerability databases locally to enable fast offline analysis and using VEX documents to differentiate between technical vulnerabilities and actual contextual risks. It also integrates with identity

    Dependency-Track is a software composition analysis platform that ingests SBOMs (which can be generated from lockfiles) to identify known vulnerabilities, offering database mirroring, severity reporting, and CI/CD integration—covering the core need for dependency vulnerability scanning, though it requires an SBOM pre-processing step rather than directly parsing lockfiles itself.

    JavaVulnerability Database ManagementKnown Exploited Vulnerability Catalogs
    Auf GitHub ansehen↗3,612
  • npm/cliAvatar von npm

    npm/cli

    9,846Auf GitHub ansehen↗

    This project is a command line interface for managing, installing, and publishing JavaScript packages to a remote registry. It serves as a dependency resolution tool, a software registry publishing client, and a security auditor for Node.js development workflows. The tool distinguishes itself by providing integrated monorepo workspace management and a comprehensive registry authentication client that supports multi-factor authentication. It enables detailed control over the software supply chain through provenance attestations, package signature verification, and the generation of a Software

    npm CLI includes an integrated security audit feature that scans package-lock.json for known vulnerabilities and provides severity reports with remediation suggestions, fitting the lockfile vulnerability scanner category within the JavaScript/Node.js ecosystem.

    JavaScriptDependency Auditing
    Auf GitHub ansehen↗9,846

Related searches

  • Schwachstellen- und Dependency-Scanning
  • Scanner für Container-Schwachstellen
  • ein Tool zum Scannen von Container-Image-Layern
  • IaC-Security-Scanner
  • Open-Source-Scanner für Sicherheitslücken
  • Vulnerability-Scanner mit Vorlagen
  • ein Tool zur Generierung von SBOMs
  • ein Tool zum Aufspüren von Secrets im Quellcode