Ross ROSS = Recommend OSS · open-source software intelligence for agents

zema1/watchvuln

一个高价值漏洞采集与推送服务 | Collect valueable vulnerabilities and push them to various services observed · 2026-08-28

github.com/zema1/watchvuln · Go · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

62/100

  • Activity 54
  • Release rhythm 56
  • Longevity 89
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 29
  • age_days: 1257
  • days_rel: 292
  • days_push: 280
  • n_releases_24m: 10

Full methodology

Adoption not part of the score

1885 stars · 229 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

WatchVuln is a self-hosted Go service that scrapes high-quality vulnerability sources (Aliyun AVD, Chaitin, OSCS, Qianxin TI, Seebug, CISA KEV, and more), filters for high-value high-severity vulns, deduplicates, and pushes alerts. It supports delivery via DingTalk, WeCom, Lark, Lanxin, ServerChan, PushPlus, Slack, and Telegram bots.

Use cases

  • monitor high-risk CVEs and get pushed to my dingtalk group
  • get notified when CISA KEV adds a new exploited vulnerability
  • filter out noise from threat intelligence RSS feeds and only see valuable vulns
  • self-hosted vulnerability alert service for a security team
  • push new POC-disclosed vulnerabilities to a feishu bot
  • track updates to vulnerabilities that later meet severity criteria

When to choose

  • you need curated, deduplicated high-severity vulnerability alerts rather than raw CVE feeds
  • your team communicates on DingTalk, WeCom, Lark, Slack, or Telegram
  • you want a self-hosted, low-maintenance Go service with Docker deployment

When to avoid

  • you need a full vulnerability management or scanning platform
  • you require sources not covered by its built-in scrapers and cannot contribute them
  • you need per-user dashboards rather than chat-bot push notifications

Facets

service · maturity active

web-scraping monitoring alerting security webhook scheduling security monitoring self-hosted self-hosted go cli vulnerability-intelligence threat-intelligence cve-monitoring dingtalk-bot lark-bot wecom-bot telegram-bot slack-webhook automation docker linux

1 source

Member repositories

RepositoryRoleHealth v2
zema1/watchvulnmain62

For agents

markdown · JSON · MCP: product_card(name="zema1/watchvuln")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem