{"repo":"murphysecurity/murphysec","free":true,"listed":false,"github":"https://github.com/murphysecurity/murphysec","clone":"git clone https://github.com/murphysecurity/murphysec.git","description":"An open source tool focused on software supply chain security. 墨菲安全专注于软件供应链安全，具备专业的软件成分分析（SCA）、漏洞检测、专业漏洞库。","language":"Go","stars":1752,"topics":["security","scanner","dependency","vulnerability-detection","software-supply-chain","sca","software-composition-analysis","codescan"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"中文 EN MurphySec CLI is used for detecting vulnerable dependencies from the command-line, and also can be integrated into your CI/CD pipeline. Features 1. Analyze dependencies being used by your project, including direct and indirect dependencies 2. Detect known vulnerabilities in project dependencies Screenshots - CLI scan result - scan result page Table of Contents 1. Supported languages 2. How it works 3. Working Scenarios 4. Getting Started 5. Command Introduction 6. Communication 7. License Supported languages Currently supports Java, JavaScript, Golang. Other development languages will be gradually supported in the future. Want to learn more about language support? check out our documentation How it works 1. MurphySec CLI obtains the dependency information of your project mainly by building the project or parsing the package manifest files. 1. The dependency information of the project will be uploaded to the server, and the dependencies with security issues in the project will be identified through the vulnerability knowledge base maintained by MurphySec. Note: MurphySec CLI will only send the dependencies and basic information of your project to server for identifying the dependencies with security issues, and will not upload any code snippets. Working Scenarios 1. To detect security issues in your code locally 2. To detect security issues in CI/CD pipeline Learn how to integrate MurphySec CLI in Jenkins Getting Started 1. Install MurphySec CLI Visit the GitHub Releases","default_branch":null,"files":null,"tree":[],"storefront":"/r/murphysecurity","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/murphysecurity/murphysec/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}