pkg.soopen package index

brew / rank 9252

Install cve-bin-tool with Homebrew, Nix

Scans binaries and SBOMs for known vulnerabilities and prepares reports. Version 3.4 via Homebrew; verified 2026-07-15. Also installable with nix: nix profile install nixpkgs#cve-bin-tool.

install

Additional install commands

macOS

Homebrewverified · 100%
brew install cve-bin-tool

local Homebrew formula metadata

Linux

Nixverified · 92%
nix profile install nixpkgs#cve-bin-tool

nixpkgs package indexes · pkgs/by-name/cv/cve-bin-tool/package.nix · source: api.github.com

overview

Package summary

Scans binaries and SBOMs for known vulnerabilities and prepares reports

Commands and aliases

  • csv2cve
  • cve-bin-tool
  • mismatch

history

Project history and usage

CVE Binary Tool is an OpenSSF vulnerability-scanning tool that detects known vulnerable components in binaries, package lists, and SBOMs, then reports matching CVEs.

Project history

The GitHub repository was created in January 2019. Official documentation describes the tool as using NVD plus sources such as Red Hat, OSV, GitLab Advisory Database, and Curl vulnerability data.

Adoption history

The project is documented for pip installation, GitHub Actions usage, and package-manager distribution through Homebrew and Nix in the supplied facts, making it usable in local scans and CI pipelines.

How it is used

Users scan directories, files, SBOMs, package lists, and language dependency manifests; the tool can also generate SBOM and VEX outputs and run with cached or offline vulnerability data.

Why package nerds care

CVE Binary Tool is relevant to package maintainers because it connects binary/package inventory, SBOM formats, vulnerability databases, and CI reporting in a single command-line workflow.

Timeline

  • 2019: GitHub repository created.
  • 2019: CVE Binary Tool 0.3.0 appears in GitHub releases.
  • 2024: CVE Binary Tool 3.4 appears in GitHub releases.
  • 2025: v3.4.1rc0 appears as a pre-release.

Related projects

  • OpenSSF, NVD, OSV, GitLab Advisory Database, SPDX, CycloneDX, OpenVEX

security posture

No protected-tool coverage found yet

No matching local secret-handling manifest was found for cve-bin-tool. Nucleus package metadata is still published here so future coverage has a stable package URL.

Install behavior

  • No Homebrew bottle metadata was recorded.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

executables

Installed executables

CommandKindExposureNote
csv2cveexecutableindexed executableDiscovered from the local executable index.
cve-bin-toolexecutableindexed executableDiscovered from the local executable index.
mismatchexecutableindexed executableDiscovered from the local executable index.

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-08-03
manager version3.4
manager updated2026-07-15
local dataunknown
upstreamnot available
latest detectednot detected
  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keybrew:cve-bin-tool
Version3.4
Package managerHomebrew
Homepagehttps://github.com/ossf/cve-bin-tool
Repositoryhttps://github.com/ossf/cve-bin-tool
Last updated2026-07-15T13:37:09Z
Pulseupdated
Bottlenot recorded
Servicenone declared

source database matches

Other package-manager records

Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.

Nix95%

cve-bin-tool

nix profile install nixpkgs#cve-bin-tool
  • normalized package name match
  • Matched by: Cve Bin Tool
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/cv/cve-bin-tool/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • cross-ecosystem install command graph
  • curated package history
  • external package-manager database matches
  • pkg.so package database
  • pkgdb category and tag curation