List of sources Veracode SCA fetches vulnerability information from
The SCA Vulnerability Database catalogs all of the open-source libraries along with their associated vulnerabilities for the following sources:
| Language | Package Managers | Sources | |
| Java | Maven | Maven Central: https://search.maven.org | |
| Gradle | |||
| Ant | |||
| Jars | |||
| Scala | SBT | Maven Central: https://search.maven.org | |
| Go | Trash | GitHub (GoLang): https://github.com https://index.golang.org/ | |
| Glide | |||
| GoVendor | |||
| GoDep | |||
| go get | |||
| Dep | |||
| Go Mod | |||
| Python | pip | PyPi: https://pypi.org | |
| Pipenv | |||
| JavaScript | node.js | NPM: https://www.npmjs.com Bower: https://bower.io | |
| Yarn | |||
| Bower | |||
| Objective-C | CocoaPods | Cocoa Pods: https://cocoapods.org | |
| Swift | CocoaPods | Cocoa Pods: https://cocoapods.org | |
| Ruby | Bundler | Ruby Gems: https://rubygems.org | |
| PHP | Composer | PHP: https://packagist.org | |
| C/C++ | Make | .SO files found in the packages in the following links http://ftp.redhat.com/redhat/linux/ https://dl.fedoraproject.org/pub/epel/ http://mirror.centos.org/centos/ | |
| C# | Nuget | Nuget: https://www.nuget.org | |
| DLLs | |||
| .NET | NuGet | Nuget: https://www.nuget.org |
Note: If a particular library is not an open source library, it will not be analyzed by our researchers and hence will not be included in our Vulnerability Database.
Steps to confirm for the source of the Library:
****************************************************
1. Get information about the library, for example using Google.
2. Determine the language.
3. Check which source matches the library.
4. Search for the library in that source.
If the library does not appear in any of the searches, then it is highly unlikely that it is open-source or supported by Veracode SCA.
Related Articles
How to address some commonly flagged SCA findings? 5.75KNumber of Views SCA Results 644Number of Views How to get listed in the Verified Directory 713Number of Views How to generate Swagger client code when using multiple Veracode APIs together 2.87KNumber of Views Getting a perfect score of 100 and no flaws for my Python Application. Are we good? 246Number of Views
This topic isn't available in this community.
Related Topics
Ask the Community
Get answers, share a use case, discuss your favorite features, or get input from the Community.
.png)