Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
Vulfy — 🐺 Vulfy – 빠른 Rust 기반 패키지 버전 스캐너 | Kitploit
도구/GitHubGitHub/mindpatch/vulfy
Vulnerability ScannersVulnerability AnalysisCode AnalysisDevSecOpsSupply Chain Security
GitHubmindpatch/vulfy

Vulfy

🐺 Vulfy – 빠른 Rust 기반 패키지 버전 스캐너

저장소 보기
163121년 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
Vulfy 로고

🐺 Vulfy

빠르고, 여러 언어를 지원하는, 복잡함 없는 취약점 스캐너.

Release License: MIT Rust CI


🚀 Vulfy란 무엇인가요?

Vulfy는 9가지 프로그래밍 언어에 걸쳐 프로젝트 의존성에서 알려진 보안 문제를 검사하는 초고속 취약점 스캐너입니다. 최대 성능을 위해 Rust로 제작되었으며 OSV.dev 데이터베이스와 통합되어 정확하고 최신의 취약점 정보를 제공합니다.

✨ 주요 기능

  • 🔥 초고속 - 동시 스캐닝을 지원하는 비동기 Rust 성능
  • 🌍 다중 에코시스템 지원 - npm, Python, Rust, Java, Go, Ruby, C/C++, PHP, .NET
  • 📊 다양한 출력 형식 - 다양한 사용 사례를 위한 Table, JSON, CSV, SARIF
  • 🎯 OSV.dev 통합 - Google의 Open Source Vulnerabilities 데이터베이스에서 제공하는 실제 취약점 데이터
  • ⚡ 제로 구성 - 기본 설정 그대로 동작하며, 필요한 것만 설정
  • 🔄 CI/CD 지원 - 자동화 파이프라인에 적합한 완벽한 종료 코드와 형식
  • 🤖 자동화 및 모니터링 - 스마트 알림과 함께하는 지속적인 Git 저장소 모니터링
  • 📋 고급 정책 엔진 - 사용자 정의 취약점 필터링 및 보안 정책
  • 🔔 다중 플랫폼 알림 - Discord, Slack, webhook 통합

📚 문서

📖 전체 문서 - 종합 가이드, 튜토리얼 및 API 참조

빠른 탐색

  • 🚀 5분 빠른 시작 - 즉시 스캔 시작
  • ⚙️ 설치 가이드 - 모든 설치 방법
  • 📋 CLI 참조 - 전체 명령어 문서
  • 🤖 자동화 설정 - 지속적인 모니터링
  • 🔧 구성 스키마 - 전체 구성 참조

📦 설치

옵션 1: 사전 빌드된 바이너리 (권장)

# Linux/WSL
curl -LO https://github.com/mindPatch/vulfy/releases/latest/download/vulfy-linux-x86_64.tar.gz
tar -xzf vulfy-linux-x86_64.tar.gz
sudo mv vulfy /usr/local/bin/

# macOS (Intel)
curl -LO https://github.com/mindPatch/vulfy/releases/latest/download/vulfy-macos-x86_64.tar.gz
tar -xzf vulfy-macos-x86_64.tar.gz
sudo mv vulfy /usr/local/bin/

# macOS (Apple Silicon)
curl -LO https://github.com/mindPatch/vulfy/releases/latest/download/vulfy-macos-aarch64.tar.gz
tar -xzf vulfy-macos-aarch64.tar.gz
sudo mv vulfy /usr/local/bin/

옵션 2: Cargo 사용

cargo install vulfy

옵션 3: 소스에서 빌드

git clone https://github.com/mindPatch/vulfy.git
cd vulfy
cargo build --release
sudo cp target/release/vulfy /usr/local/bin/

설치 확인:

vulfy --version
# Should output: vulfy 0.1.0

🏃‍♂️ 빠른 시작

기본 취약점 스캔

# Scan current directory
vulfy scan packages

# Scan specific directory
vulfy scan packages --path /path/to/project

# Only show high-severity vulnerabilities
vulfy scan packages --high-only

보고서 생성

# JSON for automation/CI
vulfy scan packages --format json --output security-report.json

# CSV for spreadsheet analysis
vulfy scan packages --format csv --output vulnerabilities.csv

# SARIF for GitHub Security tab
vulfy scan packages --format sarif --output vulfy.sarif

CI/CD 통합

# Fail build if high-severity vulnerabilities found
vulfy scan packages --high-only --quiet || exit 1

# Scan specific ecosystems only
vulfy scan packages --ecosystems npm,pypi --no-dev-deps

🎯 지원되는 에코시스템

에코시스템패키지 파일상태
📦 npmpackage-lock.json, yarn.lock, pnpm-lock.yaml, package.json✅
🐍 Pythonrequirements.txt, Pipfile.lock, poetry.lock, pyproject.toml✅
🦀 RustCargo.lock, Cargo.toml✅
☕ Javapom.xml, build.gradle, build.gradle.kts✅
🐹 Gogo.mod, go.sum, go.work✅
💎 RubyGemfile.lock, Gemfile, *.gemspec✅
⚙️ C/C++vcpkg.json, CMakeLists.txt, conanfile.txt🆕 신규!
🐘 PHPcomposer.json, composer.lock🆕 신규!
🔷 .NET*.csproj, packages.config, *.nuspec🆕 신규!

📋 출력 예시

보기 좋은 테이블 형식 (기본값)

🔍 Scanning for package files...
📦 Found 6 package files across 4 ecosystems

🛡️  VULNERABILITY REPORT
┌─────────────────────────────────────────┬──────────────┬──────────┬─────────────────┬──────┐
│ Title                                   │ CVE ID       │ Severity │ Package         │ Year │
├─────────────────────────────────────────┼──────────────┼──────────┼─────────────────┼──────┤
│ Remote Code Execution in lodash        │ CVE-2021-123 │ 🔥 High  │ [email protected]   │ 2021 │
│ Path Traversal in express              │ CVE-2022-456 │ 🟡 Medium│ [email protected]  │ 2022 │
│ SQL Injection in sequelize             │ CVE-2020-789 │ 🔥 High  │ [email protected] │ 2020 │
└─────────────────────────────────────────┴──────────────┴──────────┴─────────────────┴──────┘

📊 SCAN SUMMARY
• Total packages scanned: 42
• Vulnerable packages: 8
• Total vulnerabilities: 12
• 🔥 High severity: 4
• 🟡 Medium severity: 6
• 🟢 Low severity: 2

📖 모든 출력 형식 보기 - JSON, CSV, SARIF 예시


🤖 자동화 및 모니터링

Vulfy에는 Git 저장소의 지속적인 보안 모니터링을 위한 강력한 자동화 시스템이 포함되어 있습니다.

주요 자동화 기능

  • 📂 다중 저장소 모니터링 - 브랜치별 스캐닝으로 여러 Git 저장소 추적
  • ⏰ 유연한 일정 관리 - 매시간, 매일, 매주 또는 사용자 정의 cron 표현식
  • 🔔 스마트 알림 - 심각도 기반 필터링을 갖춘 풍부한 Discord/Slack 알림
  • 📋 고급 정책 엔진 - 키워드 매칭을 통한 사용자 정의 취약점 필터링
  • 🔐 인증 지원 - GitHub 토큰, SSH 키, 비공개 저장소 접근
  • 🏗️ 에코시스템 필터링 - 집중 스캔을 위한 저장소별 에코시스템 지정

빠른 자동화 설정

# Initialize automation with example configuration
vulfy automation init --with-examples

# Validate configuration
vulfy automation validate

# Run manual scan using automation config
vulfy automation run

# Start continuous monitoring
vulfy automation start --foreground

구성 예시

# Monitor multiple repositories
[[repositories]]
name = "my-web-app"
url = "https://github.com/user/my-web-app.git"
branches = ["main", "develop"]
ecosystems = ["npm", "pypi"]

[repositories.credentials]
username = "git"
token = "your_github_token_here"

# Schedule daily scans at 2:00 AM UTC
[schedule]
frequency = "daily"
time = "02:00"
timezone = "UTC"

# Discord webhook notifications
[[notifications.webhooks]]
name = "Security Alerts"
url = "https://discord.com/api/webhooks/..."
webhook_type = "discord"
enabled = true

# Advanced security policies
[[policies]]
name = "Critical Authentication Issues"
enabled = true

[policies.conditions]
title_contains = ["authentication", "auth", "bypass"]
severity = ["high", "critical"]

[policies.actions]
notify = true
priority = "critical"
custom_message = "🚨 Critical auth vulnerability detected!"

📖 전체 자동화 가이드 - 상세 설정 및 구성


🛠️ 사용법 및 구성

명령줄 옵션

vulfy scan packages [OPTIONS]

OPTIONS:
    -p, --path <PATH>              Directory to scan [default: current directory]
    -f, --format <FORMAT>          Output format: table, json, csv, summary, sarif
    -o, --output <FILE>            Save results to file
    -e, --ecosystems <LIST>        Only scan specific ecosystems (comma-separated)
    -q, --quiet                    Suppress progress output
    --high-only                    Show only high/critical severity vulnerabilities
    --no-recursive                 Don't scan subdirectories
    --no-dev-deps                  Skip development dependencies

프로젝트 구성

프로젝트 루트에 .vulfy.toml을 생성하세요:

도구 다운로드