macOS
brew install cve-bin-toollocal Homebrew formula metadata
brew
Scans binaries and SBOMs for known vulnerabilities and prepares reports. Version 3.4 via Homebrew; verified 2026-07-15. Also installable with nix: nix profile install nixpkgs#cve-bin-tool.
install
brew install cve-bin-toollocal Homebrew formula metadata
nix profile install nixpkgs#cve-bin-toolnixpkgs package indexes · cve-bin-tool · source: raw.githubusercontent.com
overview
Scans binaries and SBOMs for known vulnerabilities and prepares reports
history
CVE Binary Tool is an OpenSSF vulnerability-scanning tool that detects known vulnerable components in binaries, package lists, and SBOMs, then reports matching CVEs.
The GitHub repository was created in January 2019. Official documentation describes the tool as using NVD plus sources such as Red Hat, OSV, GitLab Advisory Database, and Curl vulnerability data.
The project is documented for pip installation, GitHub Actions usage, and package-manager distribution through Homebrew and Nix in the supplied facts, making it usable in local scans and CI pipelines.
Users scan directories, files, SBOMs, package lists, and language dependency manifests; the tool can also generate SBOM and VEX outputs and run with cached or offline vulnerability data.
CVE Binary Tool is relevant to package maintainers because it connects binary/package inventory, SBOM formats, vulnerability databases, and CI reporting in a single command-line workflow.
security posture
No matching local secret-handling manifest was found for cve-bin-tool. Nucleus package metadata is still published here so future coverage has a stable package URL.
Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.
executables
| Command | Kind | Exposure | Note |
|---|---|---|---|
csv2cve | cli | global executable | |
cve-bin-tool | cli | global executable | |
mismatch | cli | global executable |
freshness
These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.
https://github.com/ossf/cve-bin-tool
install metadata
| Package key | brew:cve-bin-tool |
|---|---|
| Version | 3.4 |
| Package manager | Homebrew |
| Package manager page | https://formulae.brew.sh/formula/cve-bin-tool |
| Homepage | https://github.com/ossf/cve-bin-tool |
| Repository | https://github.com/ossf/cve-bin-tool |
| Upstream docs | https://cve-bin-tool.readthedocs.io/en/latest |
| License | GPL-3.0-or-later |
| Source archive | https://files.pythonhosted.org/packages/5e/3e/e61d7581a0074c82536aacbdc7082fda2aa39d650998871068eb80627c3c/cve_bin_tool-3.4.tar.gz |
| Last updated | 2026-07-15T13:37:09Z |
| Pulse | updated |
| Dependencies | certifi, cryptography, libyaml, pillow, python@3.14, rpds-py |
| Build dependencies | cmake, rust |
| Bottle | available (on arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux) |
| Homebrew post-install | not defined |
| Service | none declared |
registry facts
| Source Database | Homebrew formula API |
|---|---|
| Tap | homebrew/core |
| Full Name | cve-bin-tool |
| Version Scheme | 0 |
| Revision | 1 |
| Head Version | HEAD |
| Bottle Stable Root URL | https://ghcr.io/v2/homebrew/core |
| Deprecated | no |
| Disabled | no |
| Keg Only | no |
| URL Keys |
|
source database matches
Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.
cve-bin-tool
nix profile install nixpkgs#cve-bin-toolsource trail
This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.
View the package source record on GitHub.