Automic VaultAutomic Vault

brew

cve-bin-tool mit Homebrew, Nix installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für cve-bin-tool in AI-Agent-Workflows.

Installation

Weitere Installationsbefehle

macOS

Homebrewverifiziert · 100%
brew install cve-bin-tool

local Homebrew formula metadata

Überblick

Paketzusammenfassung

Scans binaries and SBOMs for known vulnerabilities and prepares reports

Befehle und Aliase

  • csv2cve
  • cve-bin-tool
  • mismatch

Verlauf

Projektgeschichte und Nutzung

CVE Binary Tool is an OpenSSF vulnerability-scanning tool that detects known vulnerable components in binaries, package lists, and SBOMs, then reports matching CVEs.

Projektgeschichte

The GitHub repository was created in January 2019. Official documentation describes the tool as using NVD plus sources such as Red Hat, OSV, GitLab Advisory Database, and Curl vulnerability data.

Adoptionsgeschichte

The project is documented for pip installation, GitHub Actions usage, and package-manager distribution through Homebrew and Nix in the supplied facts, making it usable in local scans and CI pipelines.

Wie es verwendet wird

Users scan directories, files, SBOMs, package lists, and language dependency manifests; the tool can also generate SBOM and VEX outputs and run with cached or offline vulnerability data.

Warum Paket-Nerds sich dafür interessieren

CVE Binary Tool is relevant to package maintainers because it connects binary/package inventory, SBOM formats, vulnerability databases, and CI reporting in a single command-line workflow.

Zeitleiste

  • 2019: GitHub repository created.
  • 2019: CVE Binary Tool 0.3.0 appears in GitHub releases.
  • 2024: CVE Binary Tool 3.4 appears in GitHub releases.
  • 2025: v3.4.1rc0 appears as a pre-release.

Related projects

  • OpenSSF, NVD, OSV, GitLab Advisory Database, SPDX, CycloneDX, OpenVEX

Sicherheitslage

Noch keine Protected-Tool-Abdeckung gefunden

Für cve-bin-tool wurde kein passendes lokales Secret-Handling-Manifest gefunden. Nucleus-Paketmetadaten bleiben hier veröffentlicht, damit künftige Abdeckung eine stabile Paket-URL hat.

Installationsverhalten

  • In den Formelmetadaten ist kein Homebrew-Post-install-Hook erfasst.
  • Homebrew-Bottle-Metadaten sind für 6 Plattformziele verfügbar.
  • Installiert mit 6 Laufzeitabhängigkeiten.
  • Build-Metadaten listen 2 Build-Abhängigkeiten.

Empfohlene Prüfung

Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.

Executables

Installierte Executables

BefehlArtSichtbarkeitHinweis
csv2cvecliglobales Executable
cve-bin-toolcliglobales Executable
mismatchcliglobales Executable

Aktualität

Version und Aktualität

Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.

Seite generiert2026-07-25
Manager-Version3.4
Manager aktualisiert2026-07-15
lokale DatenOK
Upstreamnot checked
neueste erkannte Versionnicht erkannt

https://github.com/ossf/cve-bin-tool

Installationsmetadaten

Paketmetadaten

Paketschlüsselbrew:cve-bin-tool
Version3.4
PaketmanagerHomebrew
Paketmanager-Seitehttps://formulae.brew.sh/formula/cve-bin-tool
Homepagehttps://github.com/ossf/cve-bin-tool
Repositoryhttps://github.com/ossf/cve-bin-tool
Upstream-Dokumentationhttps://cve-bin-tool.readthedocs.io/en/latest
LizenzGPL-3.0-or-later
Quellarchivhttps://files.pythonhosted.org/packages/5e/3e/e61d7581a0074c82536aacbdc7082fda2aa39d650998871068eb80627c3c/cve_bin_tool-3.4.tar.gz
Zuletzt aktualisiert2026-07-15T13:37:09Z
Pulseupdated
Abhängigkeitencertifi, cryptography, libyaml, pillow, python@3.14, rpds-py
Build-Abhängigkeitencmake, rust
Bottleverfügbar (auf arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-installnicht definiert
Dienstkeiner deklariert

Registry-Fakten

Details aus der Quelldatenbank

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namecve-bin-tool
Version Scheme0
Revision1
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

Source-Datenbank-Treffer

Andere Paketmanager-Einträge

Treffer stammen aus externen Paketmanager-Indizes und bleiben von lokalen Automic-Vault-Paketlinks getrennt.

Nix95%

cve-bin-tool

nix profile install nixpkgs#cve-bin-tool
  • normalized package name match
  • Abgeglichen nach: Cve Bin Tool
nixpkgs package indexes · raw.githubusercontent.com · nixpkgs package indexes: cve-bin-tool from https://raw.githubusercontent.com/NixOS/nixpkgs/master/pkgs/top-level/all-packages.nix

Quellspur

Aus Repository-Daten generiert

Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.

Verwendete Quellen

  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment