SBOM scanning with three-state verdicts beats AFFECTED/NOT_AFFECTED
check_affected.py takes a CycloneDX SBOM and answers 'am I affected at version X?' with AFFECTED / NOT_AFFECTED / UNKNOWN — and shows you the interval that decided each verdict.
About
Software engineer building open-source tools that make data quality accessible to every team.
I created the Golden Suite — a collection of Python libraries for checking, transforming, matching, and orchestrating data. Each tool works standalone or as part of the pipeline.
Open Source Data Tools
Building tools that check, transform, match, and map data. All open source. All production-grade.
check_affected.py takes a CycloneDX SBOM and answers 'am I affected at version X?' with AFFECTED / NOT_AFFECTED / UNKNOWN — and shows you the interval that decided each verdict.
Package scanners aren't missing KEV by accident. KEV-with-ransomware is structurally less package-representable than the baseline corpus.
A fuzzy-join walkthrough for the open issue UCLA's Carceral Ecologies lab is sitting on: matching ~7,000 carceral facilities across federal datasets that share no clean key, no consistent industry code, and a lat/long column full of zipcode centroids.