Automic VaultAutomic Vault

brew

Install cve-bin-tool with Homebrew, Nix

Scans binaries and SBOMs for known vulnerabilities and prepares reports. Version 3.4 via Homebrew; verified 2026-07-15. Also installable with nix: nix profile install nixpkgs#cve-bin-tool.

install

Additional install commands

macOS

Homebrewverified · 100%
brew install cve-bin-tool

local Homebrew formula metadata

overview

Package summary

Scans binaries and SBOMs for known vulnerabilities and prepares reports

Commands and aliases

  • csv2cve
  • cve-bin-tool
  • mismatch

history

Project history and usage

CVE Binary Tool is an OpenSSF vulnerability-scanning tool that detects known vulnerable components in binaries, package lists, and SBOMs, then reports matching CVEs.

Project history

The GitHub repository was created in January 2019. Official documentation describes the tool as using NVD plus sources such as Red Hat, OSV, GitLab Advisory Database, and Curl vulnerability data.

Adoption history

The project is documented for pip installation, GitHub Actions usage, and package-manager distribution through Homebrew and Nix in the supplied facts, making it usable in local scans and CI pipelines.

How it is used

Users scan directories, files, SBOMs, package lists, and language dependency manifests; the tool can also generate SBOM and VEX outputs and run with cached or offline vulnerability data.

Why package nerds care

CVE Binary Tool is relevant to package maintainers because it connects binary/package inventory, SBOM formats, vulnerability databases, and CI reporting in a single command-line workflow.

Timeline

  • 2019: GitHub repository created.
  • 2019: CVE Binary Tool 0.3.0 appears in GitHub releases.
  • 2024: CVE Binary Tool 3.4 appears in GitHub releases.
  • 2025: v3.4.1rc0 appears as a pre-release.

Related projects

  • OpenSSF, NVD, OSV, GitLab Advisory Database, SPDX, CycloneDX, OpenVEX

security posture

No protected-tool coverage found yet

No matching local secret-handling manifest was found for cve-bin-tool. Nucleus package metadata is still published here so future coverage has a stable package URL.

Install behavior

  • No Homebrew post-install hook is recorded in formula metadata.
  • Homebrew bottle metadata is available for 6 platform targets.
  • Installs with 6 runtime dependencies.
  • Build metadata lists 2 build dependencies.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

executables

Installed executables

CommandKindExposureNote
csv2cvecliglobal executable
cve-bin-toolcliglobal executable
mismatchcliglobal executable

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-07-25
manager version3.4
manager updated2026-07-15
local dataok
upstreamnot checked
latest detectednot detected

https://github.com/ossf/cve-bin-tool

install metadata

Package metadata

Package keybrew:cve-bin-tool
Version3.4
Package managerHomebrew
Package manager pagehttps://formulae.brew.sh/formula/cve-bin-tool
Homepagehttps://github.com/ossf/cve-bin-tool
Repositoryhttps://github.com/ossf/cve-bin-tool
Upstream docshttps://cve-bin-tool.readthedocs.io/en/latest
LicenseGPL-3.0-or-later
Source archivehttps://files.pythonhosted.org/packages/5e/3e/e61d7581a0074c82536aacbdc7082fda2aa39d650998871068eb80627c3c/cve_bin_tool-3.4.tar.gz
Last updated2026-07-15T13:37:09Z
Pulseupdated
Dependenciescertifi, cryptography, libyaml, pillow, python@3.14, rpds-py
Build dependenciescmake, rust
Bottleavailable (on arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-installnot defined
Servicenone declared

registry facts

Source database details

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namecve-bin-tool
Version Scheme0
Revision1
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

source database matches

Other package-manager records

Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.

Nix95%

cve-bin-tool

nix profile install nixpkgs#cve-bin-tool
  • normalized package name match
  • Matched by: Cve Bin Tool
nixpkgs package indexes · raw.githubusercontent.com · nixpkgs package indexes: cve-bin-tool from https://raw.githubusercontent.com/NixOS/nixpkgs/master/pkgs/top-level/all-packages.nix

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment