osv-scanner
Off-the-shelfKnown-vulnerable dependencies, matched against the OSV database.
What it scans
Lockfiles and pinned dependencies, matched offline against a local copy of the OSV vulnerability database.
What it catches
- Dependencies with known vulnerabilities recorded in the OSV database.
Source and provenance
Nerlo pins and publishes each scanner's provenance so you can verify it yourself. Every scan surfaces the source, version, and install command in its report.
- Kind
- Off-the-shelf
- Source channel
- github releases (linux_amd64 binary)
- Pinned version
- 2.3.8
- License
- Apache-2.0
- Source URL
- https://github.com/google/osv-scanner