On this page
Overview
OSV-Scanner matches project dependencies against OSV.dev advisories. It scans source directories, lockfiles, SBOMs, and container images and uses OSV-Scalibr extractors across many ecosystems. Version 2.6.0 expands dependency extraction and plugin support while adding several hardening fixes.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Find vulnerable dependencies from source directories and lockfiles
The scanner extracts packages from npm, pip, Maven, Go modules, Cargo, RubyGems, and other supported manifests and lockfiles and matches their versions to OSV advisories.
Sources: [1]
Scan containers, OS packages, and SBOM inventories
It can inspect container layers and operating-system packages and process inventory formats such as SPDX and CycloneDX, extending beyond language lockfiles.
Use offline databases and guided remediation
Offline mode scans against a local OSV database without network requests after the database is available. Experimental guided remediation can propose dependency upgrades.
Sources: [1]
Best fit
Fits CI and local software-supply-chain vulnerability audits
It is useful when repositories, images, and SBOMs across multiple languages need a consistent dependency-vulnerability check before release.
Sources: [1]
Before adoption
Normal operation can send package metadata to external services
The README documents queries to OSV.dev, deps.dev, and package registries, including package names, versions, ecosystems, and some file hashes. Use offline mode when network or data-sharing policy requires it.
Sources: [1]
Official sources
- [1]OSV-Scanner 2.6.0 README(2026-10-04)
- [2]OSV-Scanner 2.6.0 release(2026-10-04)
- [3]OSV-Scanner 2.6.0 Go module(2026-10-04)
- [4]OSV-Scanner Apache 2.0 license(2026-10-04)
Supplemental curator note
Normal scans can send package metadata to OSV.dev, deps.dev, and registries. Consider offline mode for sensitive environments and use guided remediation only on trusted projects.
Try it in 3 steps
- 1
Fetch the OSV-Scanner v2.6.0 source
Pin the checkout to the stable release tag. The source module declares Go 1.27.0.
git clone --depth 1 --branch v2.6.0 https://github.com/google/osv-scanner.git osv-scanner-2.6.0 - 2
Build a local CLI binary
Build the v2 CLI inside the repository without installing it system-wide.
cd osv-scanner-2.6.0 && mkdir -p bin && go build -o bin/osv-scanner ./cmd/osv-scanner - 3
Check CLI help without performing a network scan
Validate the entry point without sending package metadata to OSV.dev or deps.dev. Review data flows and offline mode before a real scan.
cd osv-scanner-2.6.0 && ./bin/osv-scanner --help >/dev/null && echo 'OSV-Scanner CLI OK'
Growth
Growth trends · Last 30 days
11,135 Stars
Trend data is still being collected.
Development activity
Last 90 days · weekly
- Commits (last 30 days)
- 50
- Open PRs
- 13
Development activity is still being collected.
Built with
Categories and tags
Categories
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- scanner
- security-audit
- security-tools
- vulnerability-scanner
- Stars
- 11,135
- Forks
- 809
- Watchers
- 77
- Open issues
- 90
- Contributors
- 125
- Owner type
- Organization
- Primary language
- Go
- License
- Apache-2.0
- Repository last updated
- Oct 3, 2026
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- Cosmos Server6,174 Stars
2 shared tag(s) · Same language
manage home-server apps, access, protection, and backups together
Go - Trivy38,205 Stars
6 shared tag(s) · 1 shared category(s) · Same language
Scan images, filesystems, repositories, VMs, and Kubernetes for CVEs, secrets, IaC issues, and licenses
Go - OWASP Dependency-Check7,715 Stars
4 shared tag(s) · 1 shared category(s)
match project dependencies to CPE and CVE data and detect known vulnerabilities from CLI, Maven, Gradle, and other build integrations
Java - Gitleaks29,644 Stars
3 shared tag(s) · 1 shared category(s) · Same language
detect passwords, API keys, tokens, and other secrets in Git history, files, directories, and stdin
Go - Grype12,968 Stars
3 shared tag(s) · 1 shared category(s) · Same language
scan container images, filesystems, and SBOMs against vulnerability data and prioritize findings with EPSS, KEV, and VEX
Go - Syft9,633 Stars
3 shared tag(s) · 1 shared category(s) · Same language
generate SBOMs from container images, filesystems, and archives in CycloneDX, SPDX, and other formats
Go
Report incorrect information
Tell us if any listing information is incorrect or outdated.