How to fully utilize depscan's capability? #339
Replies: 4 comments 17 replies
-
@harshit-kochar have you tried Different profiles toggle different settings in cdxgen and depscan. Appsec profile is for appsec users willing to do their own research (using chen). Research profile is the recommended option to help get started with reachability analysis using default settings. |
Beta Was this translation helpful? Give feedback.
-
Thank you so much. 5.4.5 released with this fix. |
Beta Was this translation helpful? Give feedback.
-
Hello again 👋 😅 Can you please help here? Is it because the vulnerable lodash function template is not being populated in its corresponding
|
Beta Was this translation helpful? Give feedback.
-
Hello @prabhu 👋 |
Beta Was this translation helpful? Give feedback.
-
We are pocing with depscan and wanted to know what are some ways in which we can fully utilize depscan's reachability capabilities.
Setup
depscan --profile appsec --explain
Output
Depscan Output:
Depscan Universal Findings: depscan-universal.json
Other tools Output:
https://github.com/harekrishnarai/Damn-vulnerable-sca?tab=readme-ov-file#sca-scan-reports
Personal Thoughts
Beta Was this translation helpful? Give feedback.
All reactions