About this project

OSV (Open Source Vulnerabilities) is a vulnerability database and triage service maintained by Google. It aggregates vulnerability information from multiple ecosystems and provides a unified API, a web interface at osv.dev, and downloadable data dumps from a GCS bucket. The repository contains the code for running the service on Google Cloud Platform, including Go and Python services, deployment configuration, documentation, and frontend assets. Key components include the core OSV Python library, Go commands for the API, website, importer, worker, exporter, and other services, plus workers for processing OSS-Fuzz and Vanir signatures. The project also maintains language bindings for the OSV API and converters for NVD CVE, Alpine, and Debian vulnerability feeds. A separate Go-based scanner (osv-scanner) can check lockfiles, Debian Docker containers, SPDX and CycloneDX SBOMs, and git repositories against the OSV database. The project welcomes code, data, and documentation contributions, and is integrated with numerous third-party security tools such as Trivy, Renovate, Dependency-Track, and pip-audit.