Skip to main content
The Security Dataset identifies known vulnerabilities (CVEs) in the open source components your project depends on, both direct matches and transitive dependencies. Use it to catch security risk in your software supply chain before it reaches production.

What Do You Need?

SCANOSS API

Direct API access for vulnerability detection, including CPE identifiers and known CVEs.

SCANOSS-PY

Command-line tool for identifying vulnerabilities and CVEs from the terminal.

SBOM Workbench

Visual interface for comprehensive vulnerability analysis with detailed reporting and risk assessment.

Vulnerability Scanning Guide

A complete end-to-end workflow combining SCANOSS-PY and the REST API: scan a project, extract component PURLs from both matched code and declared dependencies, query for CVEs, then interpret and prioritise the findings. Need help? Contact our AI assistant