The project addresses the OWASP Top 10 security risk A9, Using Components with Known Vulnerabilities, which is often the root cause of data breaches. It supports software development organizations in regards to the secure use of open-source components during application development.
Eclipse Vulnerability Assessment Tool analyses Java and Python applications to identify, assess and mitigate the use of open-source dependencies with known vulnerabilities.
Analyses your Java and Python applications for open-source dependencies with known vulnerabilities, collects evidence regarding the execution of vulnerable code in a given application context (through the combination of static and dynamic analysis techniques), and supports developers in the mitigation of such dependencies.
The Eclipse Foundation hosts a significant number of Java projects, which makes it a natural fit for the Java-focussed project at hand.
Current license is Apache License, version 2.0.
There is no registered trademark for "vulnerability assessment tool".
All project dependencies have been subject to license reviews, hence, we do not expect any issues regarding incompatible licenses.
ECCN classifications are as follows: EU: not listed, US: 5D002
- Authentication and authorization checks
- Support of Node.js
- UI redesign
- Several meetings are scheduled with commercial development organizations
- Several presentations are scheduled (or proposed) at developer and open source events, e.g., Heise devSec(), LinuxFoundation Open Source Summit, EclipseCon