OSS TanbouSign in with GitHub

scan lockfiles, source trees, containers, and SBOMs for dependency vulnerabilities using OSV data

About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
11,135
Primary language
Go
License
Apache-2.0
Repository last updated
Oct 3, 2026
On this page

Overview

OSV-Scanner matches project dependencies against OSV.dev advisories. It scans source directories, lockfiles, SBOMs, and container images and uses OSV-Scalibr extractors across many ecosystems. Version 2.6.0 expands dependency extraction and plugin support while adding several hardening fixes.

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Key features

Find vulnerable dependencies from source directories and lockfiles

The scanner extracts packages from npm, pip, Maven, Go modules, Cargo, RubyGems, and other supported manifests and lockfiles and matches their versions to OSV advisories.

Sources: [1]

Scan containers, OS packages, and SBOM inventories

It can inspect container layers and operating-system packages and process inventory formats such as SPDX and CycloneDX, extending beyond language lockfiles.

Sources: [1][2]

Use offline databases and guided remediation

Offline mode scans against a local OSV database without network requests after the database is available. Experimental guided remediation can propose dependency upgrades.

Sources: [1]

Best fit

Fits CI and local software-supply-chain vulnerability audits

It is useful when repositories, images, and SBOMs across multiple languages need a consistent dependency-vulnerability check before release.

Sources: [1]

Before adoption

Normal operation can send package metadata to external services

The README documents queries to OSV.dev, deps.dev, and package registries, including package names, versions, ecosystems, and some file hashes. Use offline mode when network or data-sharing policy requires it.

Sources: [1]

Do not run guided remediation blindly on untrusted projects

The fix workflow may invoke package managers, scripts, or external registries. Upstream warns about untrusted projects, and 2.6.0 also hardens path traversal, archive exhaustion, parser recursion, and related scan paths.

Sources: [1][2]

Official sources

  1. [1]OSV-Scanner 2.6.0 README(2026-10-04)
  2. [2]OSV-Scanner 2.6.0 release(2026-10-04)
  3. [3]OSV-Scanner 2.6.0 Go module(2026-10-04)
  4. [4]OSV-Scanner Apache 2.0 license(2026-10-04)
Supplemental curator note

Normal scans can send package metadata to OSV.dev, deps.dev, and registries. Consider offline mode for sensitive environments and use guided remediation only on trusted projects.

Try it in 3 steps

  1. 1

    Fetch the OSV-Scanner v2.6.0 source

    Pin the checkout to the stable release tag. The source module declares Go 1.27.0.

    git clone --depth 1 --branch v2.6.0 https://github.com/google/osv-scanner.git osv-scanner-2.6.0
  2. 2

    Build a local CLI binary

    Build the v2 CLI inside the repository without installing it system-wide.

    cd osv-scanner-2.6.0 && mkdir -p bin && go build -o bin/osv-scanner ./cmd/osv-scanner
  3. 3

    Check CLI help without performing a network scan

    Validate the entry point without sending package metadata to OSV.dev or deps.dev. Review data flows and offline mode before a real scan.

    cd osv-scanner-2.6.0 && ./bin/osv-scanner --help >/dev/null && echo 'OSV-Scanner CLI OK'
Check the official README

Growth

Growth trends · Last 30 days

11,135 Stars

Trend data is still being collected.

Development activity

Last 90 days · weekly

Commits (last 30 days)
50
Open PRs
13

Development activity is still being collected.

Built with

Categories and tags

GitHub data

GitHub dataView detailed GitHub data

GitHub Topics

  • scanner
  • security-audit
  • security-tools
  • vulnerability-scanner
Stars
11,135
Forks
809
Watchers
77
Open issues
90
Contributors
125
Owner type
Organization
Primary language
Go
License
Apache-2.0
Repository last updated
Oct 3, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.

After reading this page, do you know what to do next?