VulnerableCode 是一个包含 Web 界面和 API 的软件包漏洞数据库。
VulnerableCode 提供 Web 界面和 API,用于访问已知软件包漏洞的数据库,其中包含来自上游和下游公共来源的全面信息,包括受漏洞影响的软件包以及修复漏洞的软件包。
有一个 公共 VulnerableCode 数据库 <https://public.vulnerablecode.io/>_,该项目还提供了构建你自己的数据库实例的工具。
在你的本地机器上运行起来的说明位于 入门指南 <https://vulnerablecode.readthedocs.io/en/stable/>_
VulnerableCode 文档还提供:
|Build Status| |Code License| |Data License| |Python 3.8+| |stability-wip| |Gitter chat|
.. |Build Status| image:: https://github.com/nexB/vulnerablecode/actions/workflows/main.yml/badge.svg?branch=main :target: https://github.com/nexB/vulnerablecode/actions?query=workflow%3ACI .. |Code License| image:: https://img.shields.io/badge/Code%20License-Apache--2.0-green.svg :target: https://opensource.org/licenses/Apache-2.0 .. |Data License| image:: https://img.shields.io/badge/Data%20License-CC--BY--SA--4.0-green.svg :target: https://creativecommons.org/licenses/by-sa/4.0/legalcode .. |Python 3.8+| image:: https://img.shields.io/badge/python-3.8+-green.svg :target: https://www.python.org/downloads/release/python-380/ .. |stability-wip| image:: https://img.shields.io/badge/stability-work_in_progress-lightgrey.svg .. |Gitter chat| image:: https://badges.gitter.im/gitterHQ/gitter.png :target: https://gitter.im/aboutcode-org/vulnerablecode
VulnerableCode 是一个免费且开放的开源软件包漏洞数据库,因为开源软件漏洞数据和工具本身应该是自由和开源的。
漏洞数据库传统上一直是专有的,尽管它们大多是关于自由和开源软件的。
漏洞数据库通常还包含大量价值较低的数据,这意味着大量误报信号需要大量专家审查。
漏洞数据库也大多首先关注漏洞,其次才是软件包,这使得很难确定某个漏洞是否适用于某段代码。VulnerableCode 首先关注软件包,其中包 URL(PURL)是软件包的关键和自然标识符;这使得更容易找到某个包以及它是否易受攻击。
PURL 最初是为 ScanCode 和 VulnerableCode 设计的。现在 PURL 已成为漏洞管理和包引用的 标准 <https://github.com/package-url/purl-spec>_。
VulnerableCode 的技术栈包括 Python、Django、PostgreSQL、nginx 和 Docker 以及多个库。
如果你有具体问题、建议或错误,请提交一个 GitHub issue <https://github.com/aboutcode-org/vulnerablecode/issues>_。
对于快速提问或社交,请加入 Slack <https://join.slack.com/t/aboutcode-org/shared_invite/zt-3li3bfs78-mmtKG0Qhv~G2dSlNCZW2pA>_ 上的 AboutCode 社区讨论。
对商业支持感兴趣?请联系 AboutCode 团队 <mailto:[email protected]>_。
Apache-2.0 <apache-2.0.LICENSE>_ 是整体许可证。CC-BY-SA-4.0 <cc-by-sa-4.0.LICENSE>_ 适用于参考数据集。本项目由以下机构资助、支持和赞助:
|europa| |dgconnect|
|ngi| |nlnet|
|aboutcode| |nexb|
本项目通过 NGI0 PET 基金资助,该基金由 NLnet 设立,并得到欧盟委员会下一代互联网计划的支持,由通信网络、内容和技术总局监管,资助协议编号 825310。
|ngizeropet| https://nlnet.nl/project/VulnerableCode/
本项目通过 NGI0 Discovery 基金资助,该基金由 NLnet 设立,并得到欧盟委员会下一代互联网计划的支持,由通信网络、内容和技术总局监管,资助协议编号 825322。
|ngidiscovery| https://nlnet.nl/project/vulnerabilitydatabase/
本项目通过 NGI0 Core 基金资助,该基金由 NLnet 设立,并得到欧盟委员会下一代互联网计划的支持,由通信网络、内容和技术总局监管,资助协议编号 101092990。
|ngizerocore| https://nlnet.nl/project/VulnerableCode-enhancements/
本项目通过 NGI0 Entrust 基金资助,该基金由 NLnet 设立,并得到欧盟委员会下一代互联网计划的支持,由通信网络、内容和技术总局监管,资助协议编号 101069594。
|ngizeroentrust| https://nlnet.nl/project/FederatedSoftwareMetadata/
本项目通过 NGI0 Commons 基金资助,该基金由 NLnet 设立,并得到欧盟委员会下一代互联网计划的支持,由通信网络、内容和技术总局监管,资助协议编号 101135429。额外资金由瑞士联邦教育、研究和创新秘书处(SERI)提供。
|ngizerocommons| |swiss| https://nlnet.nl/project/FederatedCodeNext/
本项目通过 NGI0 Entrust 基金资助,该基金由 NLnet 设立,并得到欧盟委员会下一代互联网计划的支持,由通信网络、内容和技术总局监管,资助协议编号 101069594。
|ngizeroentrust| https://nlnet.nl/project/CRAVEX/
.. |nlnet| image:: https://nlnet.nl/logo/banner.png :target: https://nlnet.nl :height: 50 :alt: NLnet 基金会标志
.. |ngi| image:: https://ngi.eu/wp-content/uploads/thegem-logos/logo_8269bc6efcf731d34b6385775d76511d_1x.png :target: https://ngi.eu35 :height: 50 :alt: NGI 标志
.. |nexb| image:: https://nexb.com/wp-content/uploads/2022/04/nexB.svg :target: https://nexb.com :height: 30 :alt: nexB 标志
.. |europa| image:: https://ngi.eu/wp-content/uploads/sites/77/2017/10/bandiera_stelle.png :target: http://ec.europa.eu/index_en.htm :height: 40 :alt: 欧盟标志
.. |aboutcode| image:: https://aboutcode.org/wp-content/uploads/2023/10/AboutCode.svg :target: https://aboutcode.org/ :height: 30 :alt: AboutCode 标志
.. |swiss| image:: https://www.sbfi.admin.ch/sbfi/en/_jcr_content/logo/image.imagespooler.png/1493119032540/logo.png :target: https://www.sbfi.admin.ch/sbfi/en/home/seri/seri.html :height: 40 :alt: 瑞士标志
.. |dgconnect| image:: https://commission.europa.eu/themes/contrib/oe_theme/dist/ec/images/logo/positive/logo-ec--en.svg :target: https://commission.europa.eu/about-european-commission/departments-and-executive-agencies/communications-networks-content-and-technology_en :height: 40 :alt: 欧盟委员会 DG Connect 标志
.. |ngizerocore| image:: https://nlnet.nl/image/logos/NGI0_tag.svg :target: https://nlnet.nl/core :height: 40 :alt: NGI Zero Core 标志
.. |ngizerocommons| image:: https://nlnet.nl/image/logos/NGI0_tag.svg :target: https://nlnet.nl/commonsfund/ :height: 40 :alt: NGI Zero Commons 标志
.. |ngizeropet| image:: https://nlnet.nl/image/logos/NGI0PET_tag.svg :target: https://nlnet.nl/PET :height: 40 :alt: NGI Zero PET 标志
.. |ngizeroentrust| image:: https://nlnet.nl/image/logos/NGI0Entrust_tag.svg :target: https://nlnet.nl/entrust :height: 38 :alt: NGI Zero Entrust 标志
.. |ngiassure| image:: https://nlnet.nl/image/logos/NGIAssure_tag.svg :target: https://nlnet.nl/image/logos/NGIAssure_tag.svg :height: 32 :alt: NGI Assure 标志
.. |ngidiscovery| image:: https://nlnet.nl/image/logos/NGI0Discovery_tag.svg :target: https://nlnet.nl/discovery/ :height: 40 :alt: NGI Discovery 标志