-
Notifications
You must be signed in to change notification settings - Fork 363
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
vulnerability scan of OSS source code #112
Comments
Hi, can you clarify what you mean? This scanner currently focuses on scanning the dependencies in a project, by scanning for e.g. lockfiles and package manifest files rather than scanning source code directly. We do have plans to combine this with some source code analysis (#11), with vendored code detection for C/C++ source code. |
Hi Oliver, |
Great! you can follow #82 and the linked issues there for C/C++ progress. |
OK, I will follow #82, and thanks for sharing a powerful tool, and it would be great if it could support source code analysis. |
Does osv-scanner support vulnerability scan of OSS source code?
By reading the documentation and testing, I think it is not supported, but I would like to do a double confirm, thanks !
The text was updated successfully, but these errors were encountered: