Who is using CVE Lite CLI? Share your use case #481
Replies: 2 comments 3 replies
-
|
I'm using it for LehrGrapht. It runs exclusively in the CI pipeline with each run to check early if there is something wrong. For the normal pipelines that builds/deploys I'm using with |
Beta Was this translation helpful? Give feedback.
-
|
CVE Lite is the third ScanSource in HexOps (https://github.com/Hexaxia-Labs/hexops) (our open source dev ops dashboard) alongside Grype and pnpm-audit. It runs on every project audit in local dev and CI across about 30 active projects, mostly pnpm with some npm. Two concrete wins for us:
The remediation-first design and the parent-graph walking compose well with how we already think about dependency hygiene. Rooting for Lab status. It's earned. Full writeup: https://labs.hexaxia.tech/blog/hexops-cve-lite-integration/ |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
If you are using CVE Lite CLI in your projects or at your company, we would love to hear about it.
Drop a comment below with:
No need for a long writeup — even a sentence or two helps.
This thread helps the community discover real-world adoption patterns and helps us understand where CVE Lite CLI is most useful. It also supports our goal of growing toward OWASP Lab Project status.
Thanks for being part of the project.
Beta Was this translation helpful? Give feedback.
All reactions