OSV-Scanner
Google's open software-composition scanner reads common package lockfiles, SBOMs, containers, and source directories, including vendored C or C++ dependencies and Git submodules.
Why use it
Use OSV-Scanner to catch known vulnerable libraries automatically in CI and before release, turning upgrades into a tracked gate while using offline databases when network exposure is undesirable.
Where it fits
Use testing, performance, accessibility, and diagnostic tools to remove problems players will notice.
What to check
Findings still need reachability, patch, and false-positive review, and online services may receive package metadata; pin V2 features by documented stability and do not replace code auditing with scans.