
Vulfyは、9つのプログラミング言語にわたってプロジェクトの依存関係に既知のセキュリティ問題がないかをチェックする、超高速の脆弱性スキャナーです。最高のパフォーマンスを実現するためにRustで構築されており、OSV.devデータベースと統合することで、正確で最新の脆弱性情報を提供します。
📖 完全なドキュメント - 包括的なガイド、チュートリアル、APIリファレンス
# Linux/WSL
curl -LO https://github.com/mindPatch/vulfy/releases/latest/download/vulfy-linux-x86_64.tar.gz
tar -xzf vulfy-linux-x86_64.tar.gz
sudo mv vulfy /usr/local/bin/
# macOS (Intel)
curl -LO https://github.com/mindPatch/vulfy/releases/latest/download/vulfy-macos-x86_64.tar.gz
tar -xzf vulfy-macos-x86_64.tar.gz
sudo mv vulfy /usr/local/bin/
# macOS (Apple Silicon)
curl -LO https://github.com/mindPatch/vulfy/releases/latest/download/vulfy-macos-aarch64.tar.gz
tar -xzf vulfy-macos-aarch64.tar.gz
sudo mv vulfy /usr/local/bin/
cargo install vulfy
git clone https://github.com/mindPatch/vulfy.git
cd vulfy
cargo build --release
sudo cp target/release/vulfy /usr/local/bin/
インストールの確認:
vulfy --version
# Should output: vulfy 0.1.0
# Scan current directory
vulfy scan packages
# Scan specific directory
vulfy scan packages --path /path/to/project
# Only show high-severity vulnerabilities
vulfy scan packages --high-only
# JSON for automation/CI
vulfy scan packages --format json --output security-report.json
# CSV for spreadsheet analysis
vulfy scan packages --format csv --output vulnerabilities.csv
# SARIF for GitHub Security tab
vulfy scan packages --format sarif --output vulfy.sarif
# Fail build if high-severity vulnerabilities found
vulfy scan packages --high-only --quiet || exit 1
# Scan specific ecosystems only
vulfy scan packages --ecosystems npm,pypi --no-dev-deps
🔍 Scanning for package files...
📦 Found 6 package files across 4 ecosystems
🛡️ VULNERABILITY REPORT
┌─────────────────────────────────────────┬──────────────┬──────────┬─────────────────┬──────┐
│ Title │ CVE ID │ Severity │ Package │ Year │
├─────────────────────────────────────────┼──────────────┼──────────┼─────────────────┼──────┤
│ Remote Code Execution in lodash │ CVE-2021-123 │ 🔥 High │ [email protected] │ 2021 │
│ Path Traversal in express │ CVE-2022-456 │ 🟡 Medium│ [email protected] │ 2022 │
│ SQL Injection in sequelize │ CVE-2020-789 │ 🔥 High │ [email protected] │ 2020 │
└─────────────────────────────────────────┴──────────────┴──────────┴─────────────────┴──────┘
📊 SCAN SUMMARY
• Total packages scanned: 42
• Vulnerable packages: 8
• Total vulnerabilities: 12
• 🔥 High severity: 4
• 🟡 Medium severity: 6
• 🟢 Low severity: 2
📖 すべての出力形式を見る - JSON、CSV、SARIFの例
Vulfyには、Gitリポジトリの継続的なセキュリティ監視のための強力な自動化システムが含まれています。
# Initialize automation with example configuration
vulfy automation init --with-examples
# Validate configuration
vulfy automation validate
# Run manual scan using automation config
vulfy automation run
# Start continuous monitoring
vulfy automation start --foreground
# Monitor multiple repositories
[[repositories]]
name = "my-web-app"
url = "https://github.com/user/my-web-app.git"
branches = ["main", "develop"]
ecosystems = ["npm", "pypi"]
[repositories.credentials]
username = "git"
token = "your_github_token_here"
# Schedule daily scans at 2:00 AM UTC
[schedule]
frequency = "daily"
time = "02:00"
timezone = "UTC"
# Discord webhook notifications
[[notifications.webhooks]]
name = "Security Alerts"
url = "https://discord.com/api/webhooks/..."
webhook_type = "discord"
enabled = true
# Advanced security policies
[[policies]]
name = "Critical Authentication Issues"
enabled = true
[policies.conditions]
title_contains = ["authentication", "auth", "bypass"]
severity = ["high", "critical"]
[policies.actions]
notify = true
priority = "critical"
custom_message = "🚨 Critical auth vulnerability detected!"
📖 完全な自動化ガイド - 詳細なセットアップと設定
vulfy scan packages [OPTIONS]
OPTIONS:
-p, --path <PATH> Directory to scan [default: current directory]
-f, --format <FORMAT> Output format: table, json, csv, summary, sarif
-o, --output <FILE> Save results to file
-e, --ecosystems <LIST> Only scan specific ecosystems (comma-separated)
-q, --quiet Suppress progress output
--high-only Show only high/critical severity vulnerabilities
--no-recursive Don't scan subdirectories
--no-dev-deps Skip development dependencies
プロジェクトのルートに .vulfy.toml を作成:
[scan]
ecosystems = ["npm", "pypi", "crates.io"]
min_severity = "medium"
skip_dev_deps = true
ignore_paths = ["node_modules", "vendor", ".git"]
[output]
format = "table"
color = "auto"
[api]
timeout = 30
max_concurrent = 10
retry_attempts = 3
📖 完全な設定リファレンス - 完全なスキーマドキュメント
機能リクエストがありますか? Issueを開いて ぜひご相談ください!
Vulfyは、パフォーマンスと信頼性を中核原則として構築されています:
📖 アーキテクチャ詳細解説 - 技術的な実装詳細
コントリビューションを歓迎します!バグ修正、新機能、エコシステム対応のいずれでも構いません。
git clone https://github.com/mindPatch/vulfy.git
cd vulfy
cargo build
cargo test
cargo clippy を実行📖 コントリビューションガイド - 詳細なコントリビューション手順
vulfyバイナリが実行可能であることを確認してください: chmod +x vulfyこのプロジェクトはMITライセンスの下で提供されています。詳細はLICENSEファイルを参照してください。
| エコシステム | パッケージファイル | ステータス |
|---|
| 📦 npm | package-lock.json, yarn.lock, pnpm-lock.yaml, package.json | ✅ |
| 🐍 Python | requirements.txt, Pipfile.lock, poetry.lock, pyproject.toml | ✅ |
| 🦀 Rust | Cargo.lock, Cargo.toml | ✅ |
| ☕ Java | pom.xml, build.gradle, build.gradle.kts | ✅ |
| 🐹 Go | go.mod, go.sum, go.work | ✅ |
| 💎 Ruby | Gemfile.lock, Gemfile, *.gemspec | ✅ |
| ⚙️ C/C++ | vcpkg.json, CMakeLists.txt, conanfile.txt | 🆕 新規! |
| 🐘 PHP | composer.json, composer.lock | 🆕 新規! |
| 🔷 .NET | *.csproj, packages.config, *.nuspec | 🆕 新規! |