{"repo":"XmirrorSecurity/OpenSCA-cli","free":true,"listed":false,"github":"https://github.com/XmirrorSecurity/OpenSCA-cli","clone":"git clone https://github.com/XmirrorSecurity/OpenSCA-cli.git","description":"OpenSCA is an open source software supply chain security solution that supports the detection of open source dependencies, vulnerabilities and license compliance with a widely noticed accuracy by the community.","language":"Go","stars":1125,"topics":["sca","devsecops","security","sbom","software-bill-of-materials","software-composition-analysis","software-supply-chain","software-supply-chain-security","license-compliance","cyclonedx"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"用开源的方式做开源风险治理 中文 English - 项目介绍 - 检测能力 - 下载安装 - 方式 1: 从 Releases 下载 - 方式 2: 一键安装脚本 - 方式 3: 使用包管理器(Homebrew) - 方式 4: 从源码构建 - 使用说明 - 参数说明 - 配置文件忽略路径 - 报告格式 - 使用样例 - 漏洞库文件格式 - 漏洞库字段说明 - 漏洞库配置示例 - 常见问题 - 使用OpenSCA需要配置环境变量吗？ - OpenSCA目前支持哪些漏洞库呢？ - 使用OpenSCA检测时，检测速度与哪些因素有关？ - 问题反馈\\&联系我们 - 贡献者 - 向我们贡献 项目介绍 OpenSCA 用来扫描项目的第三方组件依赖及漏洞信息。 官网：https://opensca.xmirror.cn 欢迎点亮 star ，鼓励下项目组的小伙伴们 --- 检测能力 OpenSCA 现已支持以下编程语言相关的配置文件解析及对应的包管理器，后续会逐步支持更多的编程语言，丰富相关配置文件的解析。 支持语言 包管理器 解析文件 ------------ ---------- ------------------------------------------------------------------------ Java Maven pom.xml Java Gradle .gradle .gradle.kts JavaScript Npm package-lock.json package.json yarn.lock PHP Composer composer.json composer.lock Ruby gem gemfile.lock Golang gomod go.mod go.sum Gopkg.toml Gopkg.lock Rust cargo Cargo.lock Erlang Rebar rebar.lock Python Pip Pipfile Pipfile.lock setup.py requirements.txt requirements.in 下载安装 OpenSCA-cli 支持 Windows、Linux、MacOS 等操作系统，支持 x86 64 和 arm64 架构。目前提供了以下几种安装方式： 方式 1: 从 Releases 下载 1. 从 github 或 gitee 或 gitcode 下载对应系统架构的可执行文件压缩包 2. 解压，并运行 opensca-cli 可执行文件即可。 方式 2: 一键安装脚本 - Mac/Linux 用户 - For Windows Users(need PowerShell) 方式 3: 使用包管理器(Homebrew) 方式 4: 从源码构建 克隆并源码编译(需要 go 1.18 及以上版本) 默认生成当前系统架构的程序，如需生成其他系统架构可配置环境变量后编译 - 禁用 CGO ENABLED CGO ENABLED=0 - 指定操作系统 GOOS=${OS} \\\\ darwin,liunx,windows - 指定体系架构 GOARCH=${arch} \\\\ amd64,arm64 使用说明 参数说明 参数 类型 描述 使用样例 -------- -------- ---------------- ------------------------ config string 指定配置文件路径 -config config.json path strin","default_branch":null,"files":null,"tree":[],"storefront":"/r/XmirrorSecurity","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/XmirrorSecurity/OpenSCA-cli/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}