OS

OSV-Scanner

Vulnerability scanner backed by the OSV database

Developer Tools & Git ★ 11.1k stars Easy setup Apache-2.0

OSV-Scanner is an open-source tool from Google that scans project dependencies for known vulnerabilities using the Open Source Vulnerabilities database. It runs locally and in self-hosted CI pipelines.

Key features

  • OSV database backed
  • Lockfile scanning
  • SBOM input support
  • CI friendly

Strengths

  • Released under the Apache-2.0 license
  • Easy to set up — beginner-friendly
  • First-class Docker support for quick deployment
  • Mature project with 11.1k GitHub stars

OSV-Scanner replaces

Compare OSV-Scanner

4 head-to-head comparisons.

Similar developer tools & git apps