Back to library
Test & PolishToolOpen sourceFree

OSV-Scanner

Google's open software-composition scanner reads common package lockfiles, SBOMs, containers, and source directories, including vendored C or C++ dependencies and Git submodules.

Visit official siteContent record updated Aug 3, 2026Official site reached automatically · Checked Aug 3, 2026

Why it’s here

Small teams can catch known vulnerable libraries automatically in CI and before release, turning upgrades into a tracked gate while using offline databases when network exposure is undesirable.

Best fit

Testing, performance, accessibility, and diagnostics expose friction before launch.

quality-assuranceautomationprivacy

Before you commit

Findings still need reachability, patch, and false-positive review, and online services may receive package metadata; pin V2 features by documented stability and do not replace code auditing with scans.

Search resources

Type to search the entire resource library

    Privacy settings

    This first release does not use behavioral analytics, advertising, or third-party tracking. Only your language choice and home-section state are stored in your browser.