Capabilities

C/C++

C/C++ package analysis and vulnerability scanning capabilities

Package analysis

Cataloger + EvidenceLicenseDependenciesPackage Manager Claims
DepthEdgesKindsFilesDigestsIntegrity Hash
conan-cataloger
conan.lock
TransitiveRuntime, Build
conan-cataloger
conanfile.txt
DirectRuntime
conan-info-cataloger
conaninfo.txt
DirectFlatRuntime

We support package detection for v1 and v2 formatted conan.lock files.

Vulnerability scanning

Data SourceDisclosuresFixesTrack by
Source
Package
AffectedDateVersionsDate
National Vulnerability Database (NVD)

Grype Configuration
Configuration KeyDescription
match.stock.using-cpesUse CPE package identifiers to find vulnerabilities

Next steps

Last modified November 26, 2025: allow local too invocation (d20d613)