This docker image provides the SCA tool ts-scan. ts-scan is capable of:
transitive dependency identification for PyPI, Maven, NuGet, NPM, Go, Cargo, Dart, Gradle, Visual Basic 6 and more, plus Docker image scanning via Syft.
Integrate it into CI/CD pipelines to catch vulnerabilities and license issues before release, or upload results directly to your TrustSource workspace for continuous supply-chain compliance monitoring.
copyright detection and extraction,
license detection and identification,
crypto-algorithm detection,
fingerprinting of files (SCANOSS),
yara scanning
ts-scan also may be used as an SBOM converter between different SPDX and CycloneDX versions.
PLEASE NOTE: Transformation between formats may not always be lossless!
You may store the results locally or upload them to the TrustSource Product Security platform for further processing or handling. Find more information at ts-scan documentation.