A security check for the components inside your software
Most apps use software components made by others. CyberHawk checks those components for known security problems and keeps a report of what needs attention. It gives the person maintaining the app findings to review before deciding on an update.
What needed a closer look
An app can keep working while a security problem is discovered in one of its components. The person looking after it needs to know which versions are affected, which findings are new, and which problems still need a fix.
What the check provides
- A report across projects. Check supported software projects for known problems in the components they use.
- A history of findings. Keep track of what each check found, so issues do not disappear when a new report is made.
- Proposed fixes to review. Give the person maintaining the app the information needed to decide what to update.
- A follow-up check. Keep an issue open until two complete checks no longer find it.
From a finding to a fix
If a report flags a component, the maintainer reviews the finding and the proposed change. A person must approve an update before it can proceed. Follow-up checks then confirm whether the finding is still present. A check that failed to finish cannot declare the problem fixed.
Where it stands
CyberHawk is released with public source code. Reports and finding history are kept locally. The tool gathers information; it does not automatically change the apps it checks.
Its scope is known problems in software components. It is not antivirus, and a clear report does not prove the whole app is secure. Technical setup and review belong with the person responsible for maintaining the software.
Have something like this in mind?
Tell Mark what you need people to be able to do. We can work out what to build, what it would cost, and what it will take to look after it.