vet: Policy Driven vetting of Open Source Software Components

By Abhisek Datta on 19 Apr 2024 @ Blackhat : Arsenal
πŸ’» Source Code πŸ”— Link
#supply-chain-security #open-source-security #dependency-management #sca
Focus Areas: πŸ“¦ Software Supply Chain Security , πŸ” Vulnerability Management
This Tool Demo covers following tools where the speaker has contributed or authored
VET

Abstract

vet is a tool for identifying risks in open source software supply chain. It helps engineering and security teams to identify potential issues in their open source dependencies and evaluate them against codified organisational policies.