A vulnerability scanner for container images and filesystems
-
Updated
May 22, 2026 - Go
A vulnerability scanner for container images and filesystems
Python CVE reachability, SCA triage, SBOM enrichment, and supply-chain security evidence for GitHub Actions and CI.
SBOM diff with supply-chain risk signals — flags new CVEs, typosquats, and young maintainers on changed deps. Built after axios (Mar 2026), Shai-Hulud, and xz.
VEX document crawler and aggregator
VEX statements for SUSE Observability product images. Consumable by Trivy via --vex repo.
Add a description, image, and links to the openvex topic page so that developers can more easily learn about it.
To associate your repository with the openvex topic, visit your repo's landing page and select "manage topics."