The service provides an Open Source component vulnerability database for analyzing such components within software products. Sources include public databases, the FSTEC BDU, and information from source repositories. The solution helps identify vulnerable components and assess risks as part of the Software Composition Analysis (SCA) process.
Import vulnerability data from external sources: CVE, FSTEC BDU, GitLab Advisory, GitHub Advisory, Google OSV, and more.
When loading into the database, data is normalized, cleared of duplicates, and converted to a common format; package names and versions are automatically determined.
Access vulnerability data via REST API and integrate with SCA-class tools.
Search for recently changed open-source repositories and perform static analysis of downloaded code for vulnerabilities and backdoors.
Finding and fixing vulnerabilities in used components reduces risks for critical systems and data.
Detecting component issues (including non-security ones) increases application reliability.
Timely, well-grounded decisions across the SDLC reduce delays and costs in development and operations.
Support compliance with security regulations and software license cleanliness requirements.