Google Open-Sources osv-scanner for Dependency Vulnerability Checks
A post introduces osv-scanner, Google's open-source tool that scans lockfiles, containers and vendored code against the osv.dev vulnerability database. It highlights guided remediation, call analysis, support for 11+ ecosystems, and offline scanning.
Original post · 1 min read
most devs ship code without knowing half their dependencies are ticking time bombs
osv-scanner fixes that
it scans your entire project lockfiles, containers, even vendored c/c++ code and maps every dependency against the osv.dev database
supports 11+ ecosystems. npm, pip, cargo, maven, go modules, gem. all of it.
the guided remediation feature is the real unlock... it doesn't just tell you what's broken.... it tells you exactly which version upgrades fix the most issues with the least risk
call analysis built in. so you only get alerts for vulnerable functions your code actually calls. no noise
works offline too. download the db once, scan without internet
one command to scan your whole directory:
osv-scanner scan source -r ./
github.com/google/osv-scanner