Finding vulnerabilities is easy; knowing which ones matter is the work. These guides use only public, free sources (OSV.dev, Debian/Ubuntu security trackers, CISA KEV, EPSS) and show how to go from thousands of CVEs to a list you can finish on a Friday afternoon.
npm audit is free and built in, and teams still miss vulnerabilities with it — or drown in 400 reports about dev dependencies. This is the pipeline we run ourselves: parse the lockfile into an exact list, batch-query OSV.dev, separate dev from production dependencies, and keep the output per week so you can say since when a CVE has been open.
Trivy is free, fast and finds everything — and that's exactly the problem: an average image yields hundreds of CVEs, most without a fix or in a tool that never runs. This is the configuration we use ourselves: --ignore-unfixed, severity thresholds, a .trivyignore with reason and date, a CI gate that only breaks on new critical findings, and a nightly scan of what actually runs on the host.
A scanner reports CVE-2026-1234 in libxml2. You know the vulnerable function is never called in your setup. A VEX statement is how you record that — machine-readable, with a reason, and with the date you knew it. This is the OpenVEX format in twenty lines, the four statuses and when to use them, how to sign with ssh-keygen, and how scanners use the statement to suppress noise.
A forty-line script that checks every installed package against the free OSV.dev API, backport-aware, and enriches the list with EPSS score and CISA KEV status. From 1,800 packages to the five you need to patch this week. No licence, no scanner appliance.
A scanner that sees 6.8.0 and reports 40 kernel CVEs doesn't know about Ubuntu and Debian backports. Here's how to read your kernel package's changelog yourself, compare the running kernel with the installed one, check hardware mitigations in /sys and decide when livepatch is worth it. Using the free sources: USN, Debian Security Tracker and the package changelog.
The 2026 Minimum Elements turned an SBOM into a signed, licensed, machine-verifiable artifact. Here is the full manual pipeline for one Linux host: inventory three layers, map every required field, canonicalize and sign with Ed25519, then derive VEX. It is a lot.