SolidLab
SolidLab OST

SolidLab OST

The service provides an Open Source component vulnerability database for analyzing such components within software products. Sources include public databases, the FSTEC BDU, and information from source repositories. The solution helps identify vulnerable components and assess risks as part of the Software Composition Analysis (SCA) process.

Use cases

  • Component selection. Make informed decisions about software component suitability during development.
  • CI/CD builds. Embed into pipelines to automatically scan components for vulnerabilities and licensing issues.
  • Security Gate. Formal compliance checks against security requirements before release.
  • Production monitoring. Alerts on newly discovered vulnerabilities in components used by released applications.

Key functional features

Integration with external sources

Import vulnerability data from external sources: CVE, FSTEC BDU, GitLab Advisory, GitHub Advisory, Google OSV, and more.

Data aggregation and correlation

When loading into the database, data is normalized, cleared of duplicates, and converted to a common format; package names and versions are automatically determined.

Service access

Access vulnerability data via REST API and integrate with SCA-class tools.

Open-source repository work

Search for recently changed open-source repositories and perform static analysis of downloaded code for vulnerabilities and backdoors.

Benefits of SolidLab OST

Improved security

Finding and fixing vulnerabilities in used components reduces risks for critical systems and data.

Higher quality

Detecting component issues (including non-security ones) increases application reliability.

More efficient processes

Timely, well-grounded decisions across the SDLC reduce delays and costs in development and operations.

Compliance

Support compliance with security regulations and software license cleanliness requirements.

Technical support and additional enablement services

  • Configure security analysis tools, develop custom rules, reduce false positives, and define severity levels.
  • Validate findings and prepare PoC scenarios for demonstration.
  • Consultations on application architecture and secure coding practices; development of internal policies and documentation.
  • Integrate the solution into the customer’s infrastructure (standalone or as part of a secure development platform).
  • Analyze tool findings and provide remediation recommendations.
  • Train customer specialists in secure development practices.
  • Prepare analytical reports.