Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

ยทยทFeedsยทContactยทPrivacyยทยฉ 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/mindpatch/vulfy
Vulnerability ScannersVulnerability AnalysisCode AnalysisDevSecOpsSupply Chain Security
GitHubmindpatch/vulfy

Vulfy

๐Ÿบ Vulfy โ€“ Fast Rust based package version scanner

View Repository
163121 year agoNot yet reviewed

Most Popular

View all โ†’

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools โ†’
Share
Vulfy Logo

๐Ÿบ Vulfy

Fast, cross-language vulnerability scanner that doesn't mess around.

Release License: MIT Rust CI


๐Ÿš€ What is Vulfy?

Vulfy is a lightning-fast vulnerability scanner that checks your project dependencies for known security issues across 9 programming languages. Built with Rust for maximum performance, it integrates with the OSV.dev database to provide accurate, up-to-date vulnerability information.

โœจ Key Features

  • ๐Ÿ”ฅ Lightning Fast - Async Rust performance with concurrent scanning
  • ๐ŸŒ Multi-Ecosystem Support - npm, Python, Rust, Java, Go, Ruby, C/C++, PHP, .NET
  • ๐Ÿ“Š Multiple Output Formats - Table, JSON, CSV, SARIF for different use cases
  • ๐ŸŽฏ OSV.dev Integration - Real vulnerability data from Google's Open Source Vulnerabilities database
  • โšก Zero Configuration - Works out of the box, configure only what you need
  • ๐Ÿ”„ CI/CD Ready - Perfect exit codes and formats for automated pipelines
  • ๐Ÿค– Automation & Monitoring - Continuous Git repository monitoring with smart notifications
  • ๐Ÿ“‹ Advanced Policy Engine - Custom vulnerability filtering and security policies
  • ๐Ÿ”” Multi-Platform Notifications - Discord, Slack, and webhook integrations

๐Ÿ“š Documentation

๐Ÿ“– Complete Documentation - Comprehensive guides, tutorials, and API reference

Quick Navigation

  • ๐Ÿš€ 5-Minute Quick Start - Get scanning immediately
  • โš™๏ธ Installation Guide - All installation methods
  • ๐Ÿ“‹ CLI Reference - Complete command documentation
  • ๐Ÿค– Automation Setup - Continuous monitoring
  • ๐Ÿ”ง Configuration Schema - Full configuration reference

๐Ÿ“ฆ Installation

Option 1: Pre-built Binaries (Recommended)

# Linux/WSL
curl -LO https://github.com/mindPatch/vulfy/releases/latest/download/vulfy-linux-x86_64.tar.gz
tar -xzf vulfy-linux-x86_64.tar.gz
sudo mv vulfy /usr/local/bin/

# macOS (Intel)
curl -LO https://github.com/mindPatch/vulfy/releases/latest/download/vulfy-macos-x86_64.tar.gz
tar -xzf vulfy-macos-x86_64.tar.gz
sudo mv vulfy /usr/local/bin/

# macOS (Apple Silicon)
curl -LO https://github.com/mindPatch/vulfy/releases/latest/download/vulfy-macos-aarch64.tar.gz
tar -xzf vulfy-macos-aarch64.tar.gz
sudo mv vulfy /usr/local/bin/

Option 2: Using Cargo

cargo install vulfy

Option 3: From Source

git clone https://github.com/mindPatch/vulfy.git
cd vulfy
cargo build --release
sudo cp target/release/vulfy /usr/local/bin/

Verify Installation:

vulfy --version
# Should output: vulfy 0.1.0

๐Ÿƒโ€โ™‚๏ธ Quick Start

Basic Vulnerability Scan

# Scan current directory
vulfy scan packages

# Scan specific directory
vulfy scan packages --path /path/to/project

# Only show high-severity vulnerabilities
vulfy scan packages --high-only

Generate Reports

# JSON for automation/CI
vulfy scan packages --format json --output security-report.json

# CSV for spreadsheet analysis
vulfy scan packages --format csv --output vulnerabilities.csv

# SARIF for GitHub Security tab
vulfy scan packages --format sarif --output vulfy.sarif

CI/CD Integration

# Fail build if high-severity vulnerabilities found
vulfy scan packages --high-only --quiet || exit 1

# Scan specific ecosystems only
vulfy scan packages --ecosystems npm,pypi --no-dev-deps

๐ŸŽฏ Supported Ecosystems

EcosystemPackage FilesStatus
๐Ÿ“ฆ npmpackage-lock.json, yarn.lock, pnpm-lock.yaml, package.jsonโœ…
๐Ÿ Pythonrequirements.txt, Pipfile.lock, poetry.lock, pyproject.tomlโœ…
๐Ÿฆ€ RustCargo.lock, Cargo.tomlโœ…
โ˜• Javapom.xml, build.gradle, build.gradle.ktsโœ…
๐Ÿน Gogo.mod, go.sum, go.workโœ…
๐Ÿ’Ž RubyGemfile.lock, Gemfile, *.gemspecโœ…
โš™๏ธ C/C++vcpkg.json, CMakeLists.txt, conanfile.txt๐Ÿ†• NEW!
๐Ÿ˜ PHPcomposer.json, composer.lock๐Ÿ†• NEW!
๐Ÿ”ท .NET*.csproj, packages.config, *.nuspec๐Ÿ†• NEW!

๐Ÿ“‹ Example Output

Beautiful Table Format (Default)

๐Ÿ” Scanning for package files...
๐Ÿ“ฆ Found 6 package files across 4 ecosystems

๐Ÿ›ก๏ธ  VULNERABILITY REPORT
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ Title                                   โ”‚ CVE ID       โ”‚ Severity โ”‚ Package         โ”‚ Year โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ Remote Code Execution in lodash        โ”‚ CVE-2021-123 โ”‚ ๐Ÿ”ฅ High  โ”‚ [email protected]   โ”‚ 2021 โ”‚
โ”‚ Path Traversal in express              โ”‚ CVE-2022-456 โ”‚ ๐ŸŸก Mediumโ”‚ [email protected]  โ”‚ 2022 โ”‚
โ”‚ SQL Injection in sequelize             โ”‚ CVE-2020-789 โ”‚ ๐Ÿ”ฅ High  โ”‚ [email protected] โ”‚ 2020 โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”˜

๐Ÿ“Š SCAN SUMMARY
โ€ข Total packages scanned: 42
โ€ข Vulnerable packages: 8
โ€ข Total vulnerabilities: 12
โ€ข ๐Ÿ”ฅ High severity: 4
โ€ข ๐ŸŸก Medium severity: 6
โ€ข ๐ŸŸข Low severity: 2

๐Ÿ“– See All Output Formats - JSON, CSV, SARIF examples


๐Ÿค– Automation & Monitoring

Vulfy includes a powerful automation system for continuous security monitoring of Git repositories.

Key Automation Features

  • ๐Ÿ“‚ Multi-Repository Monitoring - Track multiple Git repos with branch-specific scanning
  • โฐ Flexible Scheduling - Hourly, daily, weekly, or custom cron expressions
  • ๐Ÿ”” Smart Notifications - Rich Discord/Slack alerts with severity-based filtering
  • ๐Ÿ“‹ Advanced Policy Engine - Custom vulnerability filtering with keyword matching
  • ๐Ÿ” Authentication Support - GitHub tokens, SSH keys, private repository access
  • ๐Ÿ—๏ธ Ecosystem Filtering - Per-repository ecosystem targeting for focused scans

Quick Automation Setup

# Initialize automation with example configuration
vulfy automation init --with-examples

# Validate configuration
vulfy automation validate

# Run manual scan using automation config
vulfy automation run

# Start continuous monitoring
vulfy automation start --foreground

Example Configuration

# Monitor multiple repositories
[[repositories]]
name = "my-web-app"
url = "https://github.com/user/my-web-app.git"
branches = ["main", "develop"]
ecosystems = ["npm", "pypi"]

[repositories.credentials]
username = "git"
token = "your_github_token_here"

# Schedule daily scans at 2:00 AM UTC
[schedule]
frequency = "daily"
time = "02:00"
timezone = "UTC"

# Discord webhook notifications
[[notifications.webhooks]]
name = "Security Alerts"
url = "https://discord.com/api/webhooks/..."
webhook_type = "discord"
enabled = true
Download Tool