[proj. name] - Evaluate CVE-Bin-Tool for C/C++ repos #192
Open
Description
Need to evaluate https://github.com/intel/cve-bin-tool as a Software Composition Analysis (SCA) scanner for C/C++ repos (even if no binaries are released) to:
- Understand dependencies (SBOM)
- Figure out CVEs
- This is needed because Dependabot currently doesn't identify C/C++ dependencies.
Metadata
Assignees
Type
Projects
Status
Todo