#cve #installed #package #open #fixed #changelog #tyr

app get-cve

Tyr tools for CVE managing about installed products and their weaknesses

4 releases (2 breaking)

new 0.2.0 Oct 11, 2024
0.1.0 Oct 8, 2024
0.0.3 Oct 5, 2024

#81 in Unix APIs

Download history 435/week @ 2024-10-04 206/week @ 2024-10-11

641 downloads per month

MIT license

29KB
547 lines

Tyr - get-cve

Installation

cargo install get-cve

Purpose

This command line utility allows to explore fixed CVE on debian/redhat like OS.

The exploration is based on their changelog.

git-cve don't download CVE database to explore all open CVE on a package. There are several other good tools for this exploration.

Usage

To explore all fixed CVE for an installed package:

get-cve <package>

or if several version are installing:

get-cve <package>=<version>

Eg:

# get-cve less
[less => 590-1ubuntu0.22.04.3]
CVE-2014-9488
CVE-2022-46663
CVE-2022-48624
CVE-2024-32487
#

To explore all options run get-cve help

Future features

  • explore the next available release for a package,
  • explore the local changelog with an alternative way,
  • applies a filter on CVE list (eg: get-cve less --filter 2022, for showing only CVE of year 2022)

Authors and acknowledgment

Help will be appreciated. All tools will be developed with rust technology.

License

This project is under MIT license.

Project status

This project is under development and all contributions are welcome.

These tools are provided without any guaranties.

Dependencies

~6–8.5MB
~140K SLoC