OSV-Scanner
Vulnerability scanner written in Go using the Open Source Vulnerabilities (OSV) database by Google.
Why consider OSV-Scanner?
OSV-Scanner is an open-source vulnerability scanner written in Go by Google. OSV-Scanner checks project lockfiles (package.json, pom.xml, Cargo.lock, go.mod) and container SBOMs against the distributed Open Source Vulnerabilities (OSV) database to identify known security advisories.
Learn OSV-Scanner by building
Practical setup notes, real use cases, and copy-ready examples in one focused guide.
In this guide2 sections
Overview of OSV-Scanner
OSV-Scanner detects open-source CVEs across multi-language dependency manifests.
Quickstart
go install github.com/google/osv-scanner/cmd/osv-scanner@latestosv-scanner -r /path/to/projectOSV-Scanner is licensed under the Apache License Version 2.0.
Related tools
More options with a similar category or technology profile.
boringproxy
Simple, self-hosted reverse proxy and tunnel manager for exposing private web services securely.
OWASP ModSecurity
Open-source Web Application Firewall (WAF) engine providing cross-platform HTTP security inspection.
OpenCTI
Open-source platform for managing cyber threat intelligence knowledge and STIX2 relationships.
Maltrail
Malicious traffic detection system utilizing public blacklists and heuristic traffic behavior analysis.