You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: README.md
+5-4Lines changed: 5 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -75,7 +75,7 @@ If you want to try the latest code from
75
75
76
76
Pip will install the python requirements for you, but for some types of extraction we use system libraries. If you have difficulties extracting files, you may want to look at our [additional Requirements lists for Linux and Windows](#additional-requirements).
77
77
78
-
On first usage (and by default, once per day) The tool will download vulnerability data from [a set of known vulnerability data sources](https://github.com/intel/cve-bin-tool/blob/main/doc/MANUAL.md#data-sources). Due to reliability issues with NVD, as of release 3.3 we will be using our own NVD mirror at [https://cveb.in/](https://cveb.in/) by default rather than contacting NVD directly. If you wish to get data directly from the NVD servers you must [provide your own NVD_API_KEY](https://github.com/intel/cve-bin-tool/blob/main/doc/MANUAL.md#--nvd-api-key-nvd_api_key) to use their API.
78
+
On first usage (and by default, once per day), the tool will download vulnerability data from [a set of known vulnerability data sources](https://github.com/intel/cve-bin-tool/blob/main/doc/MANUAL.md#data-sources). Due to reliability issues with NVD, as of release 3.3, we will be using our own NVD mirror at [https://cveb.in/](https://cveb.in/) by default rather than contacting NVD directly. If you wish to get data directly from the NVD servers, you must [provide your own NVD_API_KEY](https://github.com/intel/cve-bin-tool/blob/main/doc/MANUAL.md#--nvd-api-key-nvd_api_key) to use their API.
79
79
80
80
If you are using a release prior to 3.3 that does not use our mirror, please use an NVD_API_KEY as described above.
81
81
@@ -123,7 +123,7 @@ The [SBOM generation how-to guide](https://github.com/intel/cve-bin-tool/blob/ma
123
123
124
124
### Generating a VEX
125
125
126
-
As well as scanning VEX, CVE Binary Tool can be used to generate an VEX from a scan as follows:
126
+
As well as scanning VEX, CVE Binary Tool can be used to generate a VEX from a scan as follows:
127
127
128
128
```bash
129
129
cve-bin-tool --vex-type <vex_type> --vex-output <vex_filename><other scan options as required>
@@ -137,7 +137,7 @@ The [VEX generation how-to guide](https://github.com/intel/cve-bin-tool/blob/mai
137
137
### Triaging vulnerabilities
138
138
139
139
The `--vex-file` option can be used to add extra triage data like remarks, comments etc. while scanning a directory so that output will reflect this triage data and you can save time of re-triaging (Usage: `cve-bin-tool --vex-file test.json /path/to/scan`).
140
-
The supported format is the [CycloneDX](https://cyclonedx.org/capabilities/vex/),[CSAF](https://oasis-open.github.io/csaf-documentation/) and [OpenVEX](https://edu.chainguard.dev/open-source/sbom/what-is-openvex/) VEX format which can be generated using the `--vex-output` option.
140
+
The supported formats are the [CycloneDX](https://cyclonedx.org/capabilities/vex/),[CSAF](https://oasis-open.github.io/csaf-documentation/) and [OpenVEX](https://edu.chainguard.dev/open-source/sbom/what-is-openvex/) VEX formats which can be generated using the `--vex-output` option.
141
141
142
142
Typical usage:
143
143
@@ -385,7 +385,7 @@ The tool does not guarantee that any vulnerabilities reported are actually prese
385
385
386
386
Users can add triage information to reports to mark issues as false positives, indicate that the risk has been mitigated by configuration/usage changes, and so on.
387
387
388
-
Triage details can be re-used on other projects so, for example, triage on a Linux base image could be applied to multiple containers using that image.
388
+
Triage details can be reused on other projects so, for example, triage on a Linux base image could be applied to multiple containers using that image.
389
389
390
390
For more information and usage of triage information with the tool kindly have a look [here](https://cve-bin-tool.readthedocs.io/en/latest/triaging_process.html).
391
391
@@ -508,6 +508,7 @@ Output:
508
508
specify type of software bill of materials (sbom) to generate (default: spdx)
0 commit comments