GithubHelp home page GithubHelp logo

ochronasec / ochrona_vs Goto Github PK

View Code? Open in Web Editor NEW
3.0 1.0 0.0 1.29 MB

Ochrona VS Code Extension

Home Page: https://ochrona.dev

License: MIT License

TypeScript 100.00%
ochrona security vulnerability-scanners dependency-analysis python vscode-extension vscode developer-tools pipfile requirements security-tools supply-chain

ochrona_vs's Introduction

Ochrona

This plugin is designed to operate as part of Ochrona Security, a solution for validating the dependencies used in python projects.

Ochrona requires a license to operate. We offer a free-tier license which allows up to 25 scans per month. You can sign up for an API key at https://ochrona.dev.

Learn more at Ochrona.dev

Usage

This Extension adds the Ochrona command which will detect all known python dependencies files and check them against Ochrona's repository of known python vulnerabilities.

In the command palette (CMD + SHIFT + P), type Ochrona. run ochrona

Features

Ochrona supports the following file types:

  • *requirements*.txt
  • Pipfile.lock
  • poetry.lock

A warning is displayed if a vulnerability is discovered. vulns found alert

A brief report is included in the VS Code Output tab for any discovered vulnerabilities. vulns found output

You can re-run the plugin by clicking the Ochrona Status Bar Icon. vulns found sb vulns not found sb

Extension Settings

An Ochrona API key is required for use of this extension. You may register for a free license at Ochrona.dev.

To set this open the VS Code Settings (Code -> Preferences -> Settings) or (CMD + ,) settings

Demo

demo

Release Notes

0.0.6

  • Short-circuit run if no files are found.

0.0.5

  • Added support for poetry.lock files.

0.0.4

  • Fixed bug in requirements.txt file parsing.
  • Adding warning when API Key is missing.
  • Stop spinner if request fails.

0.0.3

  • Added new invalid requirements.txt patterns.

0.0.2

  • Updated for new Ochrona API.

0.0.1

  • Support for checking *requirement*.txt and Pipfile.lock files for known python vulnerabilities.

ochrona_vs's People

Contributors

dependabot[bot] avatar ochronasec avatar

Stargazers

 avatar  avatar  avatar

Watchers

 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.