Hacker News new | ask | show | jobs
by taleodor 10 days ago
We support this with ReARM - https://rearmhq.com/

It's an open-core product (there is an option to self-host FOSS ReARM CE yourself) that gives you per-release vulnerability posture. It consumes various artifacts (e.g., SBOMs) generated during CI phase and does scan on them, doesn't need access to source code. Apart from SBOMs it consumes files with findings from other tools (reports in SARIF format, VDRs, VEXs).