开源软件供应链安全工具 Vet
Vet 是一个开源工具,帮助开发者和安全工程师识别软件供应链中的风险。它支持 npm、PyPI 等生态系统,并提供实时恶意包检测和自定义安全策略功能。Vet 免费可用,并与主流 CI/CD 工具集成。 2025-6-3 05:30:13 Author: www.helpnetsecurity.com(查看原文) 阅读量:2 收藏

Vet is an open source tool designed to help developers and security engineers spot risks in their software supply chains. It goes beyond traditional software composition analysis by detecting known vulnerabilities and flagging malicious packages.

vet supply chain security

Vet supports several ecosystems, including npm, PyPI, Maven, Go, Docker, and GitHub Actions, making it useful across many types of projects.

One of Vet’s key features is its use of real-time malicious package detection, powered by SafeDep Cloud. It also lets users define custom security policies using CEL (Common Expression Language), giving teams more control over how rules are applied. Built with DevSecOps in mind, Vet works with popular CI/CD tools like GitHub Actions and GitLab CI.

Vet is available for free on GitHub.

Must read:

Subscribe to the Help Net Security ad-free monthly newsletter to stay informed on the essential open-source cybersecurity tools. Subscribe here!


文章来源: https://www.helpnetsecurity.com/2025/06/03/vet-open-source-software-supply-chain-security-tool/
如有侵权请联系:admin#unsafe.sh