Version2.3.8
Revision682
Size92.0 MB
LicenseGPL-3.0
Confinementstrict
Basecore22

Vulnerability scanner for project's dependencies


OSV-Scanner is a vulnerability scanner that examines your project's list of dependencies and reports any vulnerabilities that affect the versions you're using.

As of December 2023, it supports lockfiles from C, C++, Dart, Elixir, Go, Java, JavaScript, PHP, Python, R, Ruby, and Rust. It also supports custom lockfiles: simply write some glue code to convert your lockfile into an intermediary JSON file with a particular format, and OSV-Scanner will comprehend the latter.

After confirming that a reported vulnerability is a false positive or discovering mitigations other than upgrading the package, OSV-Scanner provides the option to suppress it so that future runs will not display it.

Update History

1.9.0 (233)2.3.8 (682)
27 Jun 2026, 09:15 UTC
1.9.0 (233)
13 Dec 2025, 09:47 UTC

Published14 Dec 2023, 12:51 UTC

Last updated18 Jun 2026, 08:30 UTC

First seen13 Dec 2025, 09:47 UTC