I've been introduced to https://rubysec.com/ which has a database
which easily integrates with builds to check for known security
vulnerabilities in third party libraries and was wondering whether
anything similar exists for go packages?

A quick search finds https://snyk.io/vuln?type=golang which appears
similar but is basically a pay service based on node.js.

Also https://www.owasp.org/index.php/OWASP_Dependency_Track_Project
looks interesting but doesn't include go.

Does such an open source version exist for go which is written in go
and integrates easily with builds?

Steve Mynott <steve.myn...@gmail.com>

