Vendor Sheet
Kaspersky Open Source Software Threats Data Feed
Kaspersky Open Source Software Threats Data Feed brings threat intelligence into DevSecOps workflows so organizations can identify malicious, compromised, vulnerable, or otherwise risky open source packages before they reach production. The text-only feed monitors repositories including PyPI, npm, NuGet, Maven, Composer, Go, RPM, and Debian and correlates packages with vulnerability sources such as GitHub Security Advisories, CVE MITRE, Debian, CentOS, and Red Hat advisories. Context can include vulnerable and recommended versions, CPE/PURL identifiers, severity, system impact, compromised-package hashes, exploit hashes, and CWE information. Delivered in JSON, the feed can be integrated when packages are downloaded, during compilation and dependency checking, or when code is published, hel
