WhiteSource Unveils Free to Use Open Source Vulnerability Checker
Drag and Drop desktop tool helping WhiteSource promote responsible use of open source technology
WhiteSource, the leader in open source security and license compliance management, announced today the release of its Vulnerability Checker, a free tool that can detect if your products contain any of the 50 most critical open source vulnerabilities published in the last month.
The new standalone CLI tool is free to use and available for anyone to download directly from theย WhiteSource website. Once downloaded, the Vulnerability Checker offers users the opportunity to import and scan any library and run a quick check on the chosen development projects against last monthโs top 50 open source vulnerabilities. The Vulnerability Checker compiles a detailed report within minutes after scanning the designated libraries in your command line, highlighting detected vulnerabilities, their severity, paths, as well as links to references and suggested fixes.
Every month, open source community contributors and researchers publish dozens of new security vulnerabilities found in open source projects. In its โTop Open Source Vulnerabilities of the Monthโ reports, the WhiteSource research team outlines the vulnerabilities most impactful to users over the course of the past month to help promote awareness and facilitate properย open source security management. WhiteSourceโs new Vulnerability Checker syncs with its research teamโs monthly reports, and detects all open source components in usersโ projects, providing an immediate alert if any of the monthโs top 50 vulnerabilities are detected.
โWith our new Vulnerability Checker, we can provide everyone โ from our largest enterprise customers to young developers โ quick and accurate data on their open source usage,โ explains David Habusha, VP of Product at WhiteSource. โThis new tool is a great way for us to enable all developers to leverage the open source data continuously collected by the WhiteSource database, giving them insight into their open source usage and empowering them with the critical open source security information that they need.โ
About Mend.io
Mend.io is built for every risk, across AI and AppSec. By securing the code layer and the AI layerโand the interactions between them, where modern application risk now livesโMend.io extends proven AppSec workflows to the models, prompts, and agents inside today’s applications, delivering continuous protection across the entire AI application lifecycle.