6 guides

CVEs, SBOM & supply chain

Finding vulnerabilities is easy; knowing which ones matter is the work. These guides use only public, free sources (OSV.dev, Debian/Ubuntu security trackers, CISA KEV, EPSS) and show how to go from thousands of CVEs to a list you can finish on a Friday afternoon.

CVEs, SBOM & supply chain
intermediate · 5 min read
2026-09-16

Scanning package-lock.json for known vulnerabilities: npm audit, OSV.dev, and the gaps in both

npm audit is free and built in, and teams still miss vulnerabilities with it — or drown in 400 reports about dev dependencies. This is the pipeline we run ourselves: parse the lockfile into an exact list, batch-query OSV.dev, separate dev from production dependencies, and keep the output per week so you can say since when a CVE has been open.

npmpackage-lockosvcvesupply-chainnodejs
CVEs, SBOM & supply chain
intermediate · 5 min read
2026-09-16

Scanning container images with Trivy: in CI and on the host, without 400 findings per image

Trivy is free, fast and finds everything — and that's exactly the problem: an average image yields hundreds of CVEs, most without a fix or in a tool that never runs. This is the configuration we use ourselves: --ignore-unfixed, severity thresholds, a .trivyignore with reason and date, a CI gate that only breaks on new critical findings, and a nightly scan of what actually runs on the host.

trivydockercontainerscvecisupply-chain
CVEs, SBOM & supply chain
intermediate · 6 min read
2026-09-16

Writing a VEX statement (and why the date matters more than the status)

A scanner reports CVE-2026-1234 in libxml2. You know the vulnerable function is never called in your setup. A VEX statement is how you record that — machine-readable, with a reason, and with the date you knew it. This is the OpenVEX format in twenty lines, the four statuses and when to use them, how to sign with ssh-keygen, and how scanners use the statement to suppress noise.

vexopenvexsbomcvecrasupply-chain
CVEs, SBOM & supply chain
intermediate · 5 min read
2026-09-15

Finding CVEs in your Ubuntu and Debian packages with OSV.dev — without Nessus

A forty-line script that checks every installed package against the free OSV.dev API, backport-aware, and enriches the list with EPSS score and CISA KEV status. From 1,800 packages to the five you need to patch this week. No licence, no scanner appliance.

cveosvubuntudebianepsskevdpkg
CVEs, SBOM & supply chain
intermediate · 6 min read
2026-09-15

Kernel CVEs and backports: why uname -r tells you nothing about your patch level

A scanner that sees 6.8.0 and reports 40 kernel CVEs doesn't know about Ubuntu and Debian backports. Here's how to read your kernel package's changelog yourself, compare the running kernel with the installed one, check hardware mitigations in /sys and decide when livepatch is worth it. Using the free sources: USN, Debian Security Tracker and the package changelog.

kernelcveubuntudebianbackportslivepatchreboot
CVEs, SBOM & supply chain
advanced · 5 min read
2026-09-15

Building a CISA 2026 conformant SBOM by hand: everything you do without monsys

The 2026 Minimum Elements turned an SBOM into a signed, licensed, machine-verifiable artifact. Here is the full manual pipeline for one Linux host: inventory three layers, map every required field, canonicalize and sign with Ed25519, then derive VEX. It is a lot.

sbomcisacyclonedxspdxvexed25519

← All guides