List of sources Veracode SCA fetches vulnerability information from

The SCA Vulnerability Database catalogs all of the open-source libraries along with their associated vulnerabilities for the following sources:

 

LanguagePackage ManagersSources
JavaMavenMaven Central: https://search.maven.org
Gradle
Ant 
Jars
ScalaSBTMaven Central: https://search.maven.org
GoTrashGitHub (GoLang): https://github.com
https://index.golang.org/
Glide
GoVendor
GoDep
go get
Dep
Go Mod
PythonpipPyPi: https://pypi.org 
Pipenv
JavaScriptnode.jsNPM: https://www.npmjs.com
Bower: https://bower.io
Yarn
Bower
Objective-CCocoaPodsCocoa Pods: https://cocoapods.org
SwiftCocoaPodsCocoa Pods: https://cocoapods.org
RubyBundlerRuby Gems: https://rubygems.org 
PHPComposerPHP: https://packagist.org
C/C++Make.SO files found in the packages in the following links
http://ftp.redhat.com/redhat/linux/
https://dl.fedoraproject.org/pub/epel/
http://mirror.centos.org/centos/
C#NugetNuget: https://www.nuget.org
DLLs
.NETNuGetNuget: https://www.nuget.org
 


Note: If a particular library is not an open source library, it will not be analyzed by our researchers and hence will not be included in our Vulnerability Database.

Steps to confirm for the source of the Library:
****************************************************
1. Get information about the library, for example using Google.
2. Determine the language.
3. Check which source matches the library.
4. Search for the library in that source.

If the library does not appear in any of the searches, then it is highly unlikely that it is open-source or supported by Veracode SCA.
 

 

Topics (8)

Related Topics

    Ask the Community

    Get answers, share a use case, discuss your favorite features, or get input from the Community.