Capabilities

Bitnami

Bitnami package analysis and vulnerability scanning capabilities

Package analysis

Cataloger + EvidenceLicenseDependenciesPackage Manager Claims
DepthEdgesKindsFilesDigestsIntegrity Hash
bitnami-cataloger
/opt/bitnami/**/.spdx-*.spdx
TransitiveCompleteRuntime

Since all package data is gathered from SPDX SBOMs, the quality of the package analysis is dependent on the quality of the provided SBOMs.

Vulnerability scanning

Data SourceDisclosuresFixesTrack by
Source
Package
AffectedDateVersionsDate
Bitnami Vulnerability Database

Next steps

Last modified November 26, 2025: allow local too invocation (d20d613)