{"adoption": {"forks": 645, "observed_at": "2026-08-28T04:05:31.722352+00:00", "stars": 1753}, "canonical_url": "https://ross.abutalabs.com/products/cve-bin-tool", "card": {"archived": false, "artifact_type": "cli-tool", "description": "The CVE Binary Tool helps you determine if your system includes known vulnerabilities. You can scan binaries for over 350 common, vulnerable components (openssl, libpng, libxml2, expat and others), or if you know the components used, you can get a list of known vulnerabilities associated with an SBOM or a list of components and versions.", "domain": ["security", "developer-tools"], "enriched": true, "function": ["security", "vulnerability-scanning", "cli", "developer-tools"], "health_score": 93, "homepage": "https://cve-bin-tool.readthedocs.io/en/latest/", "language": "Python", "license": "GPL-3.0", "license_family": "copyleft", "maturity": "active", "member_repos": ["ossf/cve-bin-tool"], "name": "ossf/cve-bin-tool", "platform": ["windows", "python", "cli", "cross-platform"], "pushed_at": "2026-08-26T11:49:28+00:00", "repo": "ossf/cve-bin-tool", "stars": 1753, "tags": ["cve", "sbom", "binary-analysis", "devsecops", "vulnerability-database", "supply-chain-security", "devops", "linux", "macos"], "topics": ["cve", "security", "hacktoberfest", "vulnerabilities", "cvss", "swrepo", "system-tools", "devsecops", "security-automation", "security-tools", "python", "sbom", "vulnerability", "sbom-tool"], "urls": [], "use_cases": ["scan a linux system for binaries with known cves", "check if my firmware bundles vulnerable openssl versions", "find cves from an sbom file", "audit third-party libraries in a docker image for vulnerabilities", "generate a vulnerability report for a list of components and versions", "integrate cve scanning into ci pipeline"], "what_it_is": "A Python CLI tool that scans binaries and systems for known CVEs in over 350 common open-source components like openssl, libpng, and expat. It can also check vulnerabilities for components listed in an SBOM or a component/version list.", "when_to_avoid": ["you need dynamic or runtime exploit detection rather than known-CVE matching", "you need full SCA for interpreted-language dependency trees (use a package-level SCA tool)", "you require commercial support or guaranteed SLAs"], "when_to_choose": ["you need to detect known CVEs in compiled binaries or extracted filesystems without source access", "you want an SBOM-based vulnerability check or triage of vulnerable components", "you want a free, scriptable, offline-capable scanner for CI/CD or devsecops workflows"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/cve-bin-tool", "repo": "ossf/cve-bin-tool", "role": "main", "score": 67}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:05:31.722352+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T03:28:14.497476+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "a0842ea73f3a116eff7958fbf833dd2280c366c0d8985aa05f8e1403e0f39273", "fetched_at": "2026-08-28T04:05:31.722352+00:00", "kind": "readme", "missing": false, "url": "https://github.com/ossf/cve-bin-tool"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:05:31.722352+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T03:28:14.497476+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "a0842ea73f3a116eff7958fbf833dd2280c366c0d8985aa05f8e1403e0f39273", "fetched_at": "2026-08-28T04:05:31.722352+00:00", "kind": "readme", "missing": false, "url": "https://github.com/ossf/cve-bin-tool"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T03:28:14.497476+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "a0842ea73f3a116eff7958fbf833dd2280c366c0d8985aa05f8e1403e0f39273", "fetched_at": "2026-08-28T04:05:31.722352+00:00", "kind": "readme", "missing": false, "url": "https://github.com/ossf/cve-bin-tool"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:05:31.722352+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:05:31.722352+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:05:31.722352+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T03:28:14.497476+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "a0842ea73f3a116eff7958fbf833dd2280c366c0d8985aa05f8e1403e0f39273", "fetched_at": "2026-08-28T04:05:31.722352+00:00", "kind": "readme", "missing": false, "url": "https://github.com/ossf/cve-bin-tool"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:05:31.722352+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:05:31.722352+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T03:28:14.497476+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "a0842ea73f3a116eff7958fbf833dd2280c366c0d8985aa05f8e1403e0f39273", "fetched_at": "2026-08-28T04:05:31.722352+00:00", "kind": "readme", "missing": false, "url": "https://github.com/ossf/cve-bin-tool"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:05:31.722352+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:05:31.722352+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:05:31.722352+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T03:28:14.497476+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "a0842ea73f3a116eff7958fbf833dd2280c366c0d8985aa05f8e1403e0f39273", "fetched_at": "2026-08-28T04:05:31.722352+00:00", "kind": "readme", "missing": false, "url": "https://github.com/ossf/cve-bin-tool"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:05:31.722352+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:05:31.722352+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T03:28:14.497476+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "a0842ea73f3a116eff7958fbf833dd2280c366c0d8985aa05f8e1403e0f39273", "fetched_at": "2026-08-28T04:05:31.722352+00:00", "kind": "readme", "missing": false, "url": "https://github.com/ossf/cve-bin-tool"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T03:28:14.497476+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "a0842ea73f3a116eff7958fbf833dd2280c366c0d8985aa05f8e1403e0f39273", "fetched_at": "2026-08-28T04:05:31.722352+00:00", "kind": "readme", "missing": false, "url": "https://github.com/ossf/cve-bin-tool"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T03:28:14.497476+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "a0842ea73f3a116eff7958fbf833dd2280c366c0d8985aa05f8e1403e0f39273", "fetched_at": "2026-08-28T04:05:31.722352+00:00", "kind": "readme", "missing": false, "url": "https://github.com/ossf/cve-bin-tool"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T03:28:14.497476+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "a0842ea73f3a116eff7958fbf833dd2280c366c0d8985aa05f8e1403e0f39273", "fetched_at": "2026-08-28T04:05:31.722352+00:00", "kind": "readme", "missing": false, "url": "https://github.com/ossf/cve-bin-tool"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 99, "longevity": 100, "rhythm": 8}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": [], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 2791, "days_push": 7, "days_rel": 715, "gap_med": null, "n_releases_24m": 1}, "score": 67, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}