This episode explores an open source software vulnerability scanner called cve-bin-tool, which scans binaries and component lists in your project and reports back known vulnerabilities based on data from NIST’s National Vulnerability Database (NVD) list of Common Vulnerabilities and Exposures (CVEs).
My guest is Dr. Terry Oda, a security researcher at Intel and the lead maintainer of cve-bin-tool.