Matchboxmatchbox
← Back to match

OSV-Scanner

Google's open-source scanner that matches your project's dependencies against the OSV vulnerability database.

Desktopfree

OSV-Scanner is Google's open-source command-line tool that checks a project's dependencies, container images, and OS packages against the OSV.dev vulnerability database. It supports many language ecosystems and lockfile formats, can scan offline, and suggests dependency upgrades to fix what it finds, making it useful for developers and security engineers who want dependency vulnerability checks built into their workflow.

Categories
SecurityVulnerability ScanningDeveloper Tools

Full match profile

Behind the summary, Matchbox keeps a richer profile of OSV-Scanner - the signals our matcher actually reads to decide when to surface it. It stays private; claim the listing to see and control it.

  • Problem & pain-point mapping
  • Who we surface it to (audience fit)
  • What it's a strong alternative to
  • Trust & credibility signals

Try Matchbox with your own problem

Describe what is not working - we’ll show you whether OSV-Scanner (or something else) actually fits.