logo

Announcing OSV-Scanner V2: Vulnerability scanner and remediation tool for open source

ID: 9060185d-3250-52df-9377-0db810787ff0

STIX ID: report--9060185d-3250-52df-9377-0db810787ff0

Feed Name: Google Online Security Blog

Date Published: 2025-03-17

Date Updated: 2026-04-27

Author: Kimberly Samra

...
...

This post announces OSV-Scanner V2.0.0, integrating OSV-SCALIBR to broaden dependency extraction (e.g., Node, Python wheels, Java uber jars, Go binaries), adding layer- and base image–aware scanning for Debian/Ubuntu/Alpine containers, introducing an interactive local HTML report format, and expanding guided remediation to Maven pom.xml with machine-readable outputs and new strategies. It also outlines plans to converge OSV-Scanner and OSV-SCALIBR further, expand ecosystem support, deliver full filesystem accountability for containers, integrate reachability analysis, and add VEX support, inviting community use and contributions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.