intel / cve-bin-tool

The CVE Binary Tool helps you determine if your system includes known vulnerabilities. You can scan binaries for over 200 common, vulnerable components (openssl, libpng, libxml2, expat and others), or if you know the components used, you can get a list of known vulnerabilities associated with an SBOM or a list of components and versions.
https://cve-bin-tool.readthedocs.io/en/latest/
GNU General Public License v3.0
1.19k stars 457 forks source link

fix: vulnerabilities being missed in SBOMs (fixes #4178) #4335

Closed anthonyharrison closed 1 month ago

terriko commented 1 month ago

I'll be glad to have this in, thank you. Just one question about whether the last line was meant to be a return and not a bare tuple of None.

terriko commented 1 month ago

Thanks again!