Skip to content
aicoolies logo
osv-scanner logo

osv-scanner

Google's vulnerability scanner using the OSV database

OSV-Scanner is Google's official open-source vulnerability scanner that checks your project's dependencies against the OSV.dev database — the largest open vulnerability database covering all major ecosystems. Written in Go, it supports lockfiles from npm, pip, Maven, Cargo, Go modules, and more, providing actionable remediation guidance and CI/CD integration for automated security scanning.

About osv-scanner

OSV-Scanner is an open-source vulnerability scanning tool developed by Google that uses the OSV.dev database — the most comprehensive open vulnerability database available. Unlike commercial scanners that maintain proprietary vulnerability databases with varying coverage, OSV aggregates data from dozens of sources including the National Vulnerability Database, GitHub Security Advisories, and ecosystem-specific databases for npm, PyPI, crates.io, Go, Maven, and more. This gives OSV-Scanner exceptionally broad coverage across all major programming language ecosystems.

The scanner analyzes lockfiles, SBOMs (Software Bills of Materials), and container images to identify known vulnerabilities in your dependencies. It supports package managers across the entire developer spectrum: npm and yarn for JavaScript, pip and Poetry for Python, Maven and Gradle for Java, Cargo for Rust, Go modules, NuGet for .NET, and many more. Results include severity ratings, affected version ranges, and remediation guidance with the minimum version upgrade needed to resolve each vulnerability. The guided remediation feature intelligently suggests the least disruptive upgrade path across your dependency tree.

With over 8,600 GitHub stars and Apache-2.0 licensing, OSV-Scanner integrates into CI/CD pipelines through GitHub Actions, GitLab CI, and direct CLI invocation. It can scan entire monorepos, individual packages, or container images, and supports both offline and online modes. For development teams implementing supply chain security practices — increasingly critical after high-profile incidents like the Log4j vulnerability and the recent axios compromise — OSV-Scanner provides a Google-backed, production-ready scanning foundation with no usage limits or commercial restrictions.

Pricing & Platform Specs

Pricing Summary

100% free and open-source under the Apache-2.0 license ($0 software cost). OSV-Scanner is Google's official vulnerability scanner for dependencies, containers, lockfiles, and SBOMs using the Open Source Vulnerabilities (OSV) database with zero licensing fees.

full pricing breakdown →

Supported Platforms

CLI tool for macOS, Linux, Windows. Docker image available. CI/CD integrations for GitHub Actions and GitLab.

Explore categories, tags & use cases

Developer-first security platform

Snyk is the leading developer security platform providing continuous scanning for vulnerabilities in code (SAST), open-source dependencies (SCA), container images, and infrastructure as code. Integrates directly into IDEs, Git repositories, CI/CD pipelines, and container registries. Features AI-powered fix suggestions, license compliance checking, and real-time vulnerability database. Free for individual developers with paid plans for teams. Supports 30+ programming languages.

freemium

NVIDIA's LLM vulnerability scanner and red-teaming tool

garak is NVIDIA's open-source LLM vulnerability scanner for red-teaming AI models and applications. Probes for prompt injection, data leakage, hallucination, toxicity, encoding-based attacks, and dozens of other vulnerability categories. Runs automated attack sequences against any LLM endpoint and generates detailed vulnerability reports. Features a modular probe/detector architecture that is extensible with custom attack patterns. Named after the Star Trek character known for deception.

freeOpen Source

Autonomous AI pentester for web apps and APIs

Shannon is an autonomous white-box AI pentesting tool for web applications and APIs. It analyzes authorized source code, identifies attack vectors, attempts proof-by-exploitation, and produces remediation-ready reports. Shannon Lite is AGPL-3.0 for local use, while Shannon Pro is the commercial Keygraph platform for continuous security testing.

freemiumOpen Source

Community experience

Sources & verification

Sources checked
Content verified

Verification dates are editorial checks. Routine CMS saves and automatic updatedAt timestamps do not advance them.

FAQ

What is osv-scanner?

OSV-Scanner is Google's official open-source vulnerability scanner that checks your project's dependencies against the OSV.dev database — the largest open vulnerability database covering all major ecosystems. Written in Go, it supports lockfiles from npm, pip, Maven, Cargo, Go modules, and more, providing actionable remediation guidance and CI/CD integration for automated security scanning.

Is osv-scanner free?

Yes — osv-scanner is open source and free to use. 100% free and open-source under the Apache-2.0 license ($0 software cost). OSV-Scanner is Google's official vulnerability scanner for dependencies, containers, lockfiles, and SBOMs using the Open Source Vulnerabilities (OSV) database with zero licensing fees.

Is osv-scanner open source?

Yes — osv-scanner is open source.

Is osv-scanner still maintained?

Yes — osv-scanner is active. Its listing was last verified on September 6, 2026.

What are the best osv-scanner alternatives?

The first editor-selected osv-scanner alternatives are Snyk, garak, Shannon.