Skip to content

scikit-learn-intelex - Test CVE-Bin-Tool for C/C++ repos (even if no binaries are released) #189

Open
@rozhukov

Description

@rozhukov

Need to evaluate https://github.com/intel/cve-bin-tool as a Software Composition Analysis (SCA) scanner for C/C++ repos (even if no binaries are released) to:

  • Understand dependencies (SBOM)
  • Figure out CVEs
  • This is needed because Dependabot currently doesn't identify C/C++ dependencies.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

Status

Todo

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions