Back to library
Test & PolishToolOpen sourceFree

OSV-Scanner

Google's open software-composition scanner reads common package lockfiles, SBOMs, containers, and source directories, including vendored C or C++ dependencies and Git submodules.

Visit official site
Content updated Aug 3, 2026Automated check reached the official site · Checked Aug 24, 2026

Why use it

Use OSV-Scanner to catch known vulnerable libraries automatically in CI and before release, turning upgrades into a tracked gate while using offline databases when network exposure is undesirable.

Where it fits

Use testing, performance, accessibility, and diagnostic tools to remove problems players will notice.

quality-assuranceautomationprivacy

What to check

Findings still need reachability, patch, and false-positive review, and online services may receive package metadata; pin V2 features by documented stability and do not replace code auditing with scans.

Search the site

Search resources and field guides

    Privacy settings

    Your language choice, open home-page sections, favorites, comparisons, and recent views stay in this browser. Nothing is uploaded.