OS

OSV-Scanner

Vulnerability scanner backed by the OSV database

Developer Tools & Git ★ 10.8k stars Easy setup Apache-2.0

OSV-Scanner is an open-source tool from Google that scans project dependencies for known vulnerabilities using the Open Source Vulnerabilities database. It runs locally and in self-hosted CI pipelines.

Key features

  • OSV database backed
  • Lockfile scanning
  • SBOM input support
  • CI friendly

Strengths

  • Released under the Apache-2.0 license
  • Easy to set up — beginner-friendly
  • First-class Docker support for quick deployment
  • Mature project with 10.8k GitHub stars

OSV-Scanner replaces

Compare OSV-Scanner

14 head-to-head comparisons.

Similar developer tools & git apps