OSV-Scanner
Vulnerability scanner backed by the OSV database
OSV-Scanner is an open-source tool from Google that scans project dependencies for known vulnerabilities using the Open Source Vulnerabilities database. It runs locally and in self-hosted CI pipelines.
Key features
- OSV database backed
- Lockfile scanning
- SBOM input support
- CI friendly
Strengths
- Released under the Apache-2.0 license
- Easy to set up — beginner-friendly
- First-class Docker support for quick deployment
- Mature project with 10.8k GitHub stars
OSV-Scanner replaces
Compare OSV-Scanner
14 head-to-head comparisons.
- OSV-Scanner vs Excalidraw
- OSV-Scanner vs lazygit
- OSV-Scanner vs Hoppscotch
- OSV-Scanner vs json-server
- OSV-Scanner vs Strapi
- OSV-Scanner vs NocoDB
- OSV-Scanner vs Penpot
- OSV-Scanner vs dive
- OSV-Scanner vs Windows
- OSV-Scanner vs lazydocker
- OSV-Scanner vs Trivy
- OSV-Scanner vs Grype
- OSV-Scanner vs Syft
- OSV-Scanner vs Dependency-Track
Similar developer tools & git apps
Excalidraw
Developer Tools & GitVirtual hand-drawn style whiteboard
Replaces Miro
lazygit
Developer Tools & GitSimple terminal UI for Git commands
Replaces GitKraken, Sourcetree
Hoppscotch
Developer Tools & GitOpen-source API development ecosystem
Replaces Postman, Insomnia
json-server
Developer Tools & GitFull fake REST API from a JSON file in seconds
Replaces Mockoon, Postman Mock
Strapi
Developer Tools & GitLeading open-source headless CMS
Replaces Contentful
NocoDB
Developer Tools & GitOpen-source Airtable alternative
Replaces Airtable