v0.3.3
- Vulnerability matching on Extracted packages with OSV.dev: Enable in the CLI with
--plugins=vulnmatch/osvdev - Secret extractors with validation: Anthropic API keys, Perplexity API keys, Grok xAI API keys, Docker Hub PAT, private keys,
- Inventory extractors: MacPorts, Winget, asdf package manager, Nimble
- Vuln detectors: Docker Socket Exposure
Thanks to all Patch Reward Program participants for the new plugins!
If you're interested in contributing through the PRP yourself and earning rewards, check out https://bughunters.google.com/about/rules/open-source/6436351477940224/osv-scalibr-patch-rewards-program-rules