A vulnerability scanner for container images and filesystems
-
Updated
Jun 2, 2026 - Go
A vulnerability scanner for container images and filesystems
Pure-Rust Android decompiler and security-audit suite. DEX → Java, Hermes → JavaScript. Cross-layer taint across the React Native bridge. CycloneDX SBOM + OpenVEX. CLI and MCP. Bytecode is not a security layer.
CA9 is a local evidence engine for Python AppSec triage. It sits after scanners and before engineers waste time, proving which findings matter.
SBOM diff with supply-chain risk signals — flags new CVEs, typosquats, and young maintainers on changed deps. Built after axios (Mar 2026), Shai-Hulud, and xz.
VEX document crawler and aggregator
VEX statements for SUSE Observability product images. Consumable by Trivy via --vex repo.
APK / AAB / XAPK parser and security analysis library. Signing v1–v4 + ROCA / Fermat / Wiener / batch-GCD. CycloneDX SBOM with .rodata byte anchors. OpenVEX. YARA-X. Pure Rust.
Add a description, image, and links to the openvex topic page so that developers can more easily learn about it.
To associate your repository with the openvex topic, visit your repo's landing page and select "manage topics."