Vulnfy: Open-Source Python Tool Scans Dependencies and Containers in CI/CD Pipelines
A developer has released Vulnfy, a free and open-source vulnerability scanner written in Python, designed to integrate into CI/CD pipelines. The tool automatically detects project configuration files across multiple ecosystems, including Python, Node.js, Go, PHP, Rust, and Docker. It queries the OSV batch API to check for known CVEs and can send instant alerts to Discord or Telegram channels. Vulnfy exits with a non-zero status code when vulnerabilities are found, making it suitable as a security gate in automated workflows. The project is available on GitHub and can be installed via pip.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in