1 个仓库
The process of linking specific vulnerabilities to defined software applications or assets in external managers.
Distinct from Vulnerability Mapping: Focuses on mapping to specific application assets rather than high-level compliance standards.
Explore 1 awesome GitHub repository matching security & cryptography · Application Mapping. Refine with filters or upvote what's useful.
Dependency-Track is a software composition analysis tool and vulnerability management system designed to track dependencies and supply chain risk. It functions as a platform for ingesting and analyzing CycloneDX software bills of materials to identify known vulnerabilities and license compliance issues within third-party software components. The system distinguishes itself by mirroring external vulnerability databases locally to enable fast offline analysis and using VEX documents to differentiate between technical vulnerabilities and actual contextual risks. It also integrates with identity
Maps project-level vulnerabilities to ThreadFix applications to centralize security findings.